[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#764199: UDD: XSS in bts-usertags.cgi



Package: qa.debian.org
Tags: security

https://udd.debian.org/cgi-bin/bts-usertags.cgi?tag=serious&user=jwilk%40debian.org reads:
<td>xdotool: can't send ctrl+<key> to Iceweasel</td>

"<" and ">" in the bug subject should be escaped!

--
Jakub Wilk


Reply to: