Cross-side scripting vulnerability in gitweb
no-ack.org
no-ack.org
If you run gitweb for repositories where only yourself (an people you trust) has those permissions, this vulnerability is rather harmless. But if you are running gitweb for a large FOSS project with a lot of committers, you should be aware of that issue.
http://news.ycombinator.com/item?id=2007597
Was this deliberate?
Would Cross Side Scripting come from the other side, beyond the grave? That would be quite a bit more serious.