Cross-site scripting (XSS) vulnerability in the login panel (svn/login/) in User-Friendly SVN (aka USVN) before 1.0.7 allows remote attackers to inject arbitrary web script or HTML via the username field.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4719
Reference (s):
- BID:68155
- URL: http://www.securityfocus.com/bid/68155
- http://packetstormsecurity.com/files/127177/User-Friendly-SVN-Cross-Site-Scripting.html