Multiple cross-site scripting (XSS) vulnerabilities in the web administration interface (aka Futon) in Apache CouchDB 0.8.0 through 1.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
https://exchange.xforce.ibmcloud.com/vulnerabilities/65050
http://www.vupen.com/english/advisories/2011/0263
http://www.securitytracker.com/id?1025013
http://www.securityfocus.com/bid/46066
http://www.securityfocus.com/archive/1/516058/100/0/threaded