From: glpk xypron Date: Sun, 11 Nov 2012 23:28:20 GMT Subject: [BUG] gitweb: XSS vulnerability of RSS feed Message-ID: <20121111232820.284510@gmx.net> Gitweb can be used to generate an RSS feed. Arbitrary tags can be inserted into the XML document describing the RSS feed by careful construction of the URL. Example http://server/?p=project.git&a=rss&f= The generated XML contains <script>alert(document.cookie)</script> Depending on the system used to render the XML this might lead to the execution of javascript in the security context of the gitweb server pages. Please, escape all URL parameters. Version tested: gitweb v.1.8.0.dirty with git 1.7.2.5 Best regards Heinrich Schuchardt