lib/viewvc.py in ViewVC 1.0.5 uses the content-type parameter in the HTTP request for the Content-Type header in the HTTP response, which allows remote attackers to cause content to be misinterpreted by the browser via a content-type parameter that is inconsistent with the requested object. NOTE: this issue might not be a vulnerability, since it requires attacker access to the repository that is being viewed.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Viewvc | Viewvc | 1.0.5 (including) | 1.0.5 (including) |
Viewvc | Ubuntu | gutsy | * |
Viewvc | Ubuntu | hardy | * |
Viewvc | Ubuntu | intrepid | * |
Viewvc | Ubuntu | jaunty | * |
Viewvc | Ubuntu | karmic | * |
Viewvc | Ubuntu | upstream | * |