ViewVC-1.0.2.txt...

- AV AC AU C I A
发布: 2006-10-20
修订: 2025-04-13

It was discovered that ViewVC is neither sending a charset HTTP header nor specifying a charset in the HTML body. Therefore it is possible to trick several browsers into decoding ViewVC pages UTF-7. This allows attackers to inject arbitrary UTF-7 encoded Java-Script code into the output.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息