Candidate: CVE-2011-4923 PublicDate: 2012-02-18 00:55:00 UTC References: http://www.openwall.com/lists/oss-security/2011/10/27/8 https://ubuntu.com/security/notices/USN-1249-1 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4923 Description: Cross-site scripting (XSS) vulnerability in View.pm in BackupPC 3.0.0, 3.1.0, 3.2.0, 3.2.1, and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the num parameter in a view action to index.cgi, related to the log file viewer, a different vulnerability than CVE-2011-3361. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Jamie Strandboge Assigned-to: jdstrand CVSS: Patches_backuppc: upstream: http://backuppc.cvs.sourceforge.net/viewvc/backuppc/BackupPC/lib/BackupPC/CGI/Browse.pm?r1=1.23&r2=1.24 upstream_backuppc: released (3.2.1) hardy_backuppc: released (3.0.0-4ubuntu1.3) lucid_backuppc: released (3.1.0-9ubuntu1.2) maverick_backuppc: released (3.1.0-9ubuntu2.2) natty_backuppc: released (3.2.0-3ubuntu4.2) oneiric_backuppc: released (3.2.1-1ubuntu1.1) devel_backuppc: released (3.2.1-1ubuntu2)