Affected versions:
- Apache VCL 2.1 through 2.5.1
Description:
Improper Neutralization of Input During Web Page Generation ('Cross-site
Scripting') vulnerability in Apache VCL in the User Lookup form. A user with
sufficient rights to be able to view this part of the site can craft a URL or
be
Affected versions:
- Apache VCL 2.2 through 2.5.1
Description:
Improper Neutralization of Special Elements used in an SQL Command ('SQL
Injection') vulnerability in Apache VCL. Users can modify form data submitted
when requesting a new Block Allocation such that a SELECT SQL statement is
modi
[
https://issues.apache.org/jira/browse/VCL-1127?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17937951#comment-17937951
]
ASF subversion and git services commented on VCL-1127:
--
Commit c3a6c91