oss-sec mailing list archives
CVE request: vanilla forums before 2.0.10, xss
From: Hanno Böck <hanno () hboeck de>
Date: Mon, 6 Dec 2010 01:23:02 +0100
Hi, http://vanillaforums.org/discussion/13119/vanilla-2.0.10-released/p1 Two sound like security: # # Added SafeStyles configuration to prevent XSS linkjacking # Patched potential linkbait vulnerability in dispatcher (although I don't know what a linkbait vulnerability is, maybe someone wants to enlighten me) -- Hanno Böck Blog: http://www.hboeck.de/ GPG: 3DBD3B20 Jabber/Mail: hanno () hboeck de http://schokokeks.org - professional webhosting
Attachment:
signature.asc
Description: This is a digitally signed message part.
Current thread:
- CVE request: vanilla forums before 2.0.10, xss Hanno Böck (Dec 05)
- Re: CVE request: vanilla forums before 2.0.10, xss Josh Bressers (Dec 06)
- Re: CVE request: vanilla forums before 2.0.10, xss Steven M. Christey (Dec 06)
- Re: CVE request: vanilla forums before 2.0.10, xss Josh Bressers (Dec 07)
- Re: CVE request: vanilla forums before 2.0.10, xss Steven M. Christey (Dec 06)
- Re: CVE request: vanilla forums before 2.0.10, xss Josh Bressers (Dec 06)
