{ "schema_version": "1.4.0", "id": "GHSA-837w-7698-945q", "modified": "2022-05-02T00:08:53Z", "published": "2022-05-02T00:08:53Z", "aliases": [ "CVE-2008-4325" ], "details": "lib/viewvc.py in ViewVC 1.0.5 uses the content-type parameter in the HTTP request for the Content-Type header in the HTTP response, which allows remote attackers to cause content to be misinterpreted by the browser via a content-type parameter that is inconsistent with the requested object. NOTE: this issue might not be a vulnerability, since it requires attacker access to the repository that is being viewed.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2008-4325" }, { "type": "WEB", "url": "https://www.redhat.com/archives/fedora-package-announce/2008-September/msg01101.html" }, { "type": "WEB", "url": "https://www.redhat.com/archives/fedora-package-announce/2008-September/msg01142.html" }, { "type": "WEB", "url": "http://viewvc.tigris.org/issues/show_bug.cgi?id=354" }, { "type": "WEB", "url": "http://viewvc.tigris.org/source/browse/viewvc/trunk/lib/viewvc.py?rev=2011&r1=1968&r2=1978" }, { "type": "WEB", "url": "http://viewvc.tigris.org/source/browse/viewvc?rev=1978&view=rev" }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2008/09/19/4" }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2008/09/20/1" } ], "database_specific": { "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2008-09-30T16:13:00Z" } }