CVE-2006-5442

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/10/2006
Last modified:
09/04/2025

Description

ViewVC 1.0.2 and earlier does not specify a charset in its HTTP headers or HTML documents, which allows remote attackers to conduct cross-site scripting (XSS) attacks that inject arbitrary UTF-7 encoded JavaScript code via a view.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:viewvc:viewvc:*:*:*:*:*:*:*:* 1.0.2 (including)