Zwiki: XSS vulnerability Zwiki is vulnerable to cross-site scripting attacks. zwiki 2004-12-21 2006-05-22 72315 remote 0.36.2-r1 0.36.2-r1

Zwiki is a Zope wiki-clone for easy-to-edit collaborative websites.

Due to improper input validation, Zwiki can be exploited to perform cross-site scripting attacks.

By enticing a user to read a specially-crafted wiki entry, an attacker can execute arbitrary script code running in the context of the victim's browser.

There is no known workaround at this time.

All Zwiki users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-zope/zwiki-0.36.2-r1"
Zwiki Bug Report CVE-2004-1075 vorlon078 koon lewk