Loading...
Loading...
Cross-site scripting (XSS) vulnerability in the "extra" details in the DiffSource._get_row function in lib/viewvc.py in ViewVC 1.0.x before 1.0.13 and 1.1.x before 1.1.16 allows remote authenticated users with repository commit access to inject arbitrary web script or HTML via the "function name" line.
November 19, 2012
April 29, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2012-4533
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.