This script is Copyright (C) 2007-2014 Tenable Network Security, Inc.
The remote Gentoo host is missing one or more security-related
The remote host is affected by the vulnerability described in GLSA-200703-10
(KHTML: Cross-site scripting (XSS) vulnerability)
inside the 'Title' HTML element, a related issue to the Safari error
found by Jose Avila.
When viewing a HTML page that renders unsanitized attacker-supplied
input in the page title, Konqueror and other parts of KDE will execute
theft of browser session data or cookies.
There is no known workaround at this time.
See also :
All KDElibs users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose '>=kde-base/kdelibs-3.5.5-r8'
Risk factor :
Medium / CVSS Base Score : 4.3