漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
lib/viewvc.py in ViewVC 1.0.5 uses the content-type parameter in the HTTP request for the Content-Type header in the HTTP response, which allows remote attackers to cause content to be misinterpreted by the browser via a content-type parameter that is inconsistent with the requested object. NOTE: this issue might not be a vulnerability, since it requires attacker access to the repository that is being viewed.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ViewVC 跨站脚本攻击漏洞
Vulnerability Description
ViewVC是一个基于web的CVS、SVN代码仓库浏览工具。 ViewVC 1.0.5的lib/viewvc.py运行对HTTP响应中的Content-Type头提交的请求的HTTP中的content-type参数, 远程攻击者可以通过与请求对象不一致的content-type参数来造成浏览器错误解释内容。
CVSS Information
N/A
Vulnerability Type
N/A