6 ms·
Cross-side scripting vulnerability in gitweb
- tptacek 16y agoI'm not super familiar with gitweb so I'll be the one to ask: what can you do with gitweb as a logged-in user? What's the impact of an XSS on gitweb?
- wallunit 16y agoThere is basically no login area. Gitweb is the official web interface for the source tracker git. If you have permissions to push to the repository the gitweb page is showing, you could possibly add a file to the repository, when shown on the page will inject malicious javascript code for example. If you run gitweb for repositories where only yourself (an people you trust) has those permissions, this vulnerability is rather harmless. But if you are running gitweb for a large FOSS project with a lot of committers, you should be aware of that issue.
- wccrawford 16y agoSite. Cross Site Scripting. Would Cross Side Scripting come from the other side, beyond the grave? That would be quite a bit more serious.
- DupDetector 16y agoThis seems to be a re-submission of a page by the same person: http://news.ycombinator.com/item?id=2007597 http://news.ycombinator.com/item?id=2007597 Was this deliberate?