Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
lib/viewvc.py in ViewVC 1.0.5 uses the content-type parameter in the HTTP request for the Content-Type header in the HTTP response, which allows remote attackers to cause content to be misinterpreted by the browser via a content-type parameter that is inconsistent with the requested object. NOTE: this issue might not be a vulnerability, since it requires attacker access to the repository that is being viewed.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ViewVC 跨站脚本攻击漏洞
Vulnerability Description
ViewVC是一个基于web的CVS、SVN代码仓库浏览工具。 ViewVC 1.0.5的lib/viewvc.py运行对HTTP响应中的Content-Type头提交的请求的HTTP中的content-type参数, 远程攻击者可以通过与请求对象不一致的content-type参数来造成浏览器错误解释内容。
CVSS Information
N/A
Vulnerability Type
N/A