Cross-Site Scripting Vulnerability in Dwarf HTTP Server by Dwarf Software
CVE-2006-0820

Currently unrated

Key Information:

Vendor

Gnome

Vendor
CVE Published:
13 March 2006

What is CVE-2006-0820?

The Dwarf HTTP Server version 1.3.2 contains a cross-site scripting (XSS) vulnerability that permits remote attackers to inject arbitrary web scripts or HTML into the web application. This issue arises from the server's failure to properly sanitize error messages, which can be exploited to execute malicious scripts in the context of the affected user's session, potentially leading to data theft or manipulation.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.