Rémi Perrot fixed several security related bugs in the bonsai, the Mozilla CVS query tool by web interface. Vulnerabilities include arbitrary code execution, cross-site scripting and access to configuration parameters. The Common Vulnerabilities and Exposures project identifies the following problems:
For the stable distribution (woody) these problems have been fixed in version 1.3+cvs20020224-1woody1.
The old stable distribution (potato) is not affected since it doesn't contain bonsai.
For the unstable distribution (sid) these problems have been fixed in version 1.3+cvs20030317-1.
We recommend that you upgrade your bonsai package.
MD5 checksums of the listed files are available in the original advisory.