[BUG] gitweb: XSS vulnerability of RSS feed
- From
glpk xypron <xypron.glpk@gmx.de>
- Date
- Nov 11, 2012, 23:28 UTC
- Message-ID
- <20121111232820.284510@gmx.net>
Gitweb can be used to generate an RSS feed.
Arbitrary tags can be inserted into the XML document describing the RSS feed by careful construction of the URL.
Example http://server/?p=project.git&a=rss&f=</title><script>alert(document.cookie)</script><title>
The generated XML contains <script>alert(document.cookie)</script>
Depending on the system used to render the XML this might lead to the execution of javascript in the security context of the gitweb server pages.
Please, escape all URL parameters.
Version tested: gitweb v.1.8.0.dirty with git 1.7.2.5
Best regards
Heinrich Schuchardt