CVE-2016-1236: Debian Linux

Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.

Multiple cross-site scripting (XSS) vulnerabilities in (1) revision.php, (2) log.php, (3) listing.php, and (4) comp.php in WebSVN allow context-dependent attackers to inject arbitrary web script or HTML via the name of a (a) file or (b) directory in a repository.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Websvn Websvn: any version

Published 2016-05-11. Last modified 2026-06-17.