关键信息 CVE Identifier: CVE-2012-4519 Vulnerability Type: Cross-Site Scripting (XSS) Details: Affected Component: ( parameter) Affected Versions: Not fixed in 1.4.3.3, fix will be included in the next bugfix release starting November. Additional Information: Fix Details: - SVN diff link - Code changes involve sanitizing the parameter to prevent XSS. Security Advisory Links: OSVDB Full Disclosure Security Advisories Personal Blog