Cross-site scripting (XSS) vulnerability in the “extra” details in the DiffSource._get_row function in lib/viewvc.py in ViewVC 1.0.x before 1.0.13 and 1.1.x before 1.1.16 allows remote authenticated users with repository commit access to inject arbitrary web script or HTML via the “function name” line.
bugs.debian.org/cgi-bin/bugreport.cgi?bug=691062
osvdb.org/86566
secunia.com/advisories/51041
secunia.com/advisories/51072
viewvc.tigris.org/issues/show_bug.cgi?id=515
viewvc.tigris.org/source/browse/%2Acheckout%2A/viewvc/tags/1.0.13/CHANGES
viewvc.tigris.org/source/browse/%2Acheckout%2A/viewvc/tags/1.1.16/CHANGES
viewvc.tigris.org/source/browse/viewvc?view=rev&revision=2792
viewvc.tigris.org/source/browse/viewvc?view=rev&revision=2794
www.debian.org/security/2012/dsa-2563
www.mandriva.com/security/advisories?name=MDVSA-2013:134
www.openwall.com/lists/oss-security/2012/10/21/2
www.openwall.com/lists/oss-security/2012/10/21/3
www.securityfocus.com/bid/56161
exchange.xforce.ibmcloud.com/vulnerabilities/79561
wiki.mageia.org/en/Support/Advisories/MGASA-2012-0313