Multiple cross-site scripting vulnerabilities have been reported in Roundup. A remote attacker could exploit them in order to execute arbitrary Javascript or HTML code by inciting his victim into following a specially formed link.
- CVE-2012-6130: The username content is not correctely encoded.
- CVE-2012-6131: The action_name parameter is not encoded before displaying an error message.
- CVE-2012-6132: The ok_message parameter does not correctly filtered.
- CVE-2012-6133: The "otk" parameter does not validate before returning it to the user.
The Roundup packages provided by Debian Squeeze 6.0 are vulnerable.