Cross-site scripting (XSS) vulnerability in gnatsweb.pl in Gnatsweb 4.00 and Gnats 4.1.99 allows remote attackers to inject arbitrary web script or HTML via the database parameter.
| Software | From | Fixed in |
|---|---|---|
| gnu / gnats | 4.1.99 | 4.1.99.x |
| yngve_svendsen / gnatsweb | 4.00 | 4.00.x |