{"id":"DEBIAN-CVE-2008-1468","details":"Cross-site scripting (XSS) vulnerability in namazu.cgi in Namazu before 2.0.18 allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded input, related to failure to set the charset, a different vector than CVE-2004-1318 and CVE-2001-1350. NOTE: some of these details are obtained from third party information.","modified":"2026-09-20T06:47:29.349125227Z","published":"2008-03-24T21:44:00Z","upstream":["CVE-2008-1468"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2008-1468"}],"affected":[{"package":{"name":"namazu2","ecosystem":"Debian:12","purl":"pkg:deb/debian/namazu2?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.18-0.1"}]}],"ecosystem_specific":{"urgency":"low"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2008-1468.json"}},{"package":{"name":"namazu2","ecosystem":"Debian:13","purl":"pkg:deb/debian/namazu2?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.18-0.1"}]}],"ecosystem_specific":{"urgency":"low"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2008-1468.json"}}],"schema_version":"1.9.0"}