Gentoo Linux Security Advisory GLSA 200903-20 – Multiple vulnerabilities in WebSVN allow for file overwrite and information disclosure. James Bercegay of GulfTech Security reported a Cross-site scripting (XSS) vulnerability in the getParameterisedSelfUrl() function in index.php (CVE-2008-5918) and a directory traversal vulnerability in rss.php when magic_quotes_gpc is disabled (CVE-2008-5919). Versions less than 2.1.0 are affected.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/75543/glsa-200903-20.txt
Source: https://packetstormsecurity.com/files/75543/Gentoo-Linux-Security-Advisory-200903-20.html

