Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to an RPM info display.
https://exchange.xforce.ibmcloud.com/vulnerabilities/69279
https://bugzilla.novell.com/show_bug.cgi?id=700591
http://www.securityfocus.com/bid/49236
http://support.novell.com/security/cve/CVE-2011-2644.html
http://lists.opensuse.org/opensuse-security-announce/2011-08/msg00013.html