Cross-site scripting (XSS) vulnerability in ht://dig (htdig) before 3.1.6-r7 allows remote attackers to execute arbitrary web script or HTML via the config parameter, which is not properly sanitized before it is displayed in an error message.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Htdig | Htdig | 3.1.5 (including) | 3.1.5 (including) |
Htdig | Htdig | 3.1.5_7 (including) | 3.1.5_7 (including) |
Htdig | Htdig | 3.1.5_8 (including) | 3.1.5_8 (including) |
Htdig | Htdig | 3.1.6 (including) | 3.1.6 (including) |
Htdig | Htdig | 3.2.0 (including) | 3.2.0 (including) |
Htdig | Htdig | 3.2.0b2 (including) | 3.2.0b2 (including) |
Htdig | Htdig | 3.2.0b3 (including) | 3.2.0b3 (including) |
Htdig | Htdig | 3.2.0b4 (including) | 3.2.0b4 (including) |
Htdig | Htdig | 3.2.0b5 (including) | 3.2.0b5 (including) |
Htdig | Htdig | 3.2.0b6 (including) | 3.2.0b6 (including) |
Htdig | Ubuntu | dapper | * |
Htdig | Ubuntu | devel | * |
Htdig | Ubuntu | edgy | * |
Htdig | Ubuntu | feisty | * |
Red Hat Enterprise Linux 4 | RedHat | htdig-3:3.2.0b6-3.40.1 | * |