Debian Security Advisory 1275-1 – A cross-site scripting vulnerability in zope, a web application server, could allow an attacker to inject arbitrary HTML and/or JavaScript into the victim’s web browser. This code would run within the security context of the web browser, potentially allowing the attacker to access private data such as authentication cookies, or to affect the rendering or behavior of zope web pages.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/55579/dsa-1275-1.txt
Source: https://packetstormsecurity.com/files/55579/Debian-Linux-Security-Advisory-1275-1.html

