{"id":"CVE-2006-5442","details":"ViewVC 1.0.2 and earlier does not specify a charset in its HTTP headers or HTML documents, which allows remote attackers to conduct cross-site scripting (XSS) attacks that inject arbitrary UTF-7 encoded JavaScript code via a view.","modified":"2024-06-04T04:00:19Z","published":"2006-10-21T00:07:00Z","withdrawn":"2024-06-30T15:57:10.273816Z","references":[{"type":"ADVISORY","url":"http://secunia.com/advisories/22395"},{"type":"ADVISORY","url":"http://www.hardened-php.net/advisory_102006.134.html"},{"type":"WEB","url":"http://securityreason.com/securityalert/1755"},{"type":"WEB","url":"http://viewvc.tigris.org/servlets/ReadMsg?list=announce&msgNo=5&raw=true"},{"type":"WEB","url":"http://viewvc.tigris.org/source/browse/viewvc/trunk/CHANGES?rev=HEAD"},{"type":"WEB","url":"http://www.securityfocus.com/archive/1/448762/100/0/threaded"},{"type":"WEB","url":"http://www.securityfocus.com/bid/20543"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/29576"}],"affected":[{"package":{"name":"viewvc","ecosystem":"Debian:10","purl":"pkg:deb/debian/viewvc?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.3-1"}]}],"ecosystem_specific":{"urgency":"medium"},"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2006-5442.json"}}],"schema_version":"1.7.3"}