Zope Web Application Server Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2009-5145 - Vulnerability Database
Zope Web Application Server Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2009-5145
Medium
Reference:
CVE-2009-5145
Title:
Zope Web Application Server Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:
Cross-site scripting (XSS) vulnerability in ZMI pages that use the manage_tabs_message in Zope 2.11.4 2.11.2 2.10.9 2.10.7 2.10.6 2.10.5 2.10.4 2.10.2 2.10.1 2.12.