Description
|
|
Multiple vulnerabilities have been identified in RWiki, which could be exploited by remote attackers to execute arbitrary commands or scripting code.
The first issue is due to input validation errors in various scripts when handling certain parameters, which could be exploited by attackers to cause malicious scripting code to be executed by the user's browser.
The second flaw is due to input validation errors in the editing form that fails to properly validate certain parameters, which could be exploited by malicious people to inject and execute arbitrary Ruby code with the privileges of the web server.
|