Candidate: CVE-2008-6428 PublicDate: 2009-03-06 18:30:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-6428 Description: The CGI framework in Kaya 0.4.0 allows remote attackers to inject arbitrary HTTP headers and conduct cross-site scripting (XSS) attacks via unspecified vectors. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: Patches_kaya: upstream_kaya: released (0.4.1) dapper_kaya: ignored (reached end-of-life) gutsy_kaya: needed (reached end-of-life) hardy_kaya: ignored (reached end-of-life) intrepid_kaya: not-affected (0.4.2-4) jaunty_kaya: not-affected karmic_kaya: not-affected lucid_kaya: not-affected maverick_kaya: not-affected natty_kaya: not-affected oneiric_kaya: not-affected devel_kaya: not-affected