Viewvc

Viewvc

21 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.25%
  • Published 22.07.2025 21:35:47
  • Last modified 05.08.2025 17:17:58

ViewVC is a browser interface for CVS and Subversion version control repositories. In versions 1.1.0 through 1.1.31 and 1.2.0 through 1.2.3, the standalone.py script provided in the ViewVC distribution can expose the contents of the host server's fil...

Exploit
  • EPSS 0.24%
  • Published 04.01.2023 16:15:09
  • Last modified 21.11.2024 07:44:51

ViewVC is a browser interface for CVS and Subversion version control repositories. Versions prior to 1.2.3 and 1.1.30 are vulnerable to cross-site scripting. The impact of this vulnerability is mitigated by the need for an attacker to have commit pri...

  • EPSS 0.25%
  • Published 03.01.2023 19:15:10
  • Last modified 21.11.2024 07:44:50

ViewVC, a browser interface for CVS and Subversion version control repositories, as a cross-site scripting vulnerability that affects versions prior to 1.2.2 and 1.1.29. The impact of this vulnerability is mitigated by the need for an attacker to hav...

Exploit
  • EPSS 0.41%
  • Published 03.04.2020 00:15:11
  • Last modified 21.11.2024 05:33:49

ViewVC before versions 1.1.28 and 1.2.1 has a XSS vulnerability in CVS show_subdir_lastmod support. The impact of this vulnerability is mitigated by the need for an attacker to have commit privileges to a CVS repository exposed by an otherwise truste...

Exploit
  • EPSS 0.35%
  • Published 07.11.2019 22:15:10
  • Last modified 21.11.2024 00:38:36

viewvc 1.0.3 allows improper access control to files in a repository when using the "forbidden" configuration option.

  • EPSS 0.63%
  • Published 15.03.2017 14:59:00
  • Last modified 20.04.2025 01:37:25

Cross-site scripting (XSS) vulnerability in the nav_path function in lib/viewvc.py in ViewVC before 1.0.14 and 1.1.x before 1.1.26 allows remote attackers to inject arbitrary web script or HTML via the nav_data name.

  • EPSS 1.29%
  • Published 19.11.2012 00:55:00
  • Last modified 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in the "extra" details in the DiffSource._get_row function in lib/viewvc.py in ViewVC 1.0.x before 1.0.13 and 1.1.x before 1.1.16 allows remote authenticated users with repository commit access to inject arbit...

  • EPSS 0.71%
  • Published 22.07.2012 16:55:39
  • Last modified 11.04.2025 00:51:21

The SVN revision view (lib/vclib/svn/svn_repos.py) in ViewVC before 1.1.15 does not properly handle log messages when a readable path is copied from an unreadable path, which allows remote attackers to obtain sensitive information, related to a "log ...

  • EPSS 0.44%
  • Published 22.07.2012 16:55:39
  • Last modified 11.04.2025 00:51:21

The remote SVN views functionality (lib/vclib/svn/svn_ra.py) in ViewVC before 1.1.15 does not properly perform authorization, which allows remote attackers to bypass intended access restrictions via unspecified vectors.

  • EPSS 0.5%
  • Published 23.05.2011 22:55:01
  • Last modified 11.04.2025 00:51:21

ViewVC before 1.1.11 allows remote attackers to bypass the cvsdb row_limit configuration setting, and consequently conduct resource-consumption attacks, via the limit parameter, as demonstrated by a "query revision history" request.