Monthly archive for March 2013

CVE-2012-5636 - Apache Wicket XSS vulnerability

03 Mar 2013

Severity: Important

Vendor: The Apache Software Foundation

Versions Affected: Apache Wicket 1.4.x, 1.5.x and 1.6.x

Description: It is possible for JavaScript statements to break out of a <script> tag in the rendered response. This mig...

more