{"id":"CVE-2009-0359","details":"Multiple cross-site scripting (XSS) vulnerabilities in Samizdat before 0.6.2 allow remote authenticated users to inject arbitrary web script or HTML via the (1) message title or (2) user full name.","modified":"2026-04-10T03:40:38.011209Z","published":"2009-02-17T17:30:05Z","references":[{"type":"ADVISORY","url":"http://samizdat.nongnu.org/release-notes/samizdat-0.6.1-xss-escape-title.patch"},{"type":"ADVISORY","url":"http://www.nongnu.org/samizdat/release-notes/samizdat-0.6.2.html"},{"type":"FIX","url":"http://www.nongnu.org/samizdat/release-notes/samizdat-0.6.2.html"},{"type":"FIX","url":"http://www.securityfocus.com/bid/33768"},{"type":"WEB","url":"http://osvdb.org/52022"},{"type":"WEB","url":"http://www.mail-archive.com/debian-testing-security-announce%40lists.debian.org/msg00171.html"},{"type":"WEB","url":"http://www.securityfocus.com/archive/1/500961/100/0/threaded"}],"schema_version":"1.7.5"}