PublicDate: 2005-01-10 05:00:00 UTC Candidate: CVE-2004-1075 References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1075 Description: Cross-site scripting (XSS) vulnerability in standard_error_message.dtml for Zwiki after 0.10.0rc1 to 0.36.2 allows remote attackers to inject arbitrary HTML and web script via a malformed URL, which is not properly cleansed when generating an error message. Ubuntu-Description: Notes: Priority: untriaged Discovered-by: Assigned-to: CVSS: Bugs: dapper_zope-zwiki: released (0.53-0ubuntu2) edgy_zope-zwiki: released (0.53-0ubuntu2) feisty_zope-zwiki: released (0.53-0ubuntu2) devel_zope-zwiki: released (0.53-0ubuntu2) upstream_zope-zwiki: needs-triage