Revision:  436864
Date:      2017-03-25
Time:      00:01:54Z
Committer: timur

4e23644c-cb93-4f83-9e20-5bc07ad9b39fmod_pagespeed -- critical cross-site scripting (XSS) vulnerability

mod_pagespeed developers report:

Various versions of mod_pagespeed are subject to critical cross-site scripting (XSS) vulnerability, CVE-2013-6111. This permits a hostile third party to execute JavaScript in users' browsers in context of the domain running mod_pagespeed, which could permit theft of users' cookies or data on the site.

Discovery 2013-10-04
Entry 2013-10-28