Debian Security Advisory 1486-1 – “r0t” discovered that gnatsweb, a web interface to GNU GNATS, did not correctly sanitize the database parameter in the main CGI script. This could allow the injection of arbitrary HTML, or javascript code.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/63312/dsa-1486-1.txt
Source: https://packetstormsecurity.com/files/63312/Debian-Linux-Security-Advisory-1486-1.html

