oss-sec mailing list archives

CVE request: vanilla forums before 2.0.10, xss


From: Hanno Böck <hanno () hboeck de>
Date: Mon, 6 Dec 2010 01:23:02 +0100

Hi,

http://vanillaforums.org/discussion/13119/vanilla-2.0.10-released/p1

Two sound like security:
#
# Added SafeStyles configuration to prevent XSS linkjacking
# Patched potential linkbait vulnerability in dispatcher

(although I don't know what a linkbait vulnerability is, maybe someone wants 
to enlighten me)

-- 
Hanno Böck              Blog:           http://www.hboeck.de/
GPG: 3DBD3B20           Jabber/Mail:    hanno () hboeck de

http://schokokeks.org - professional webhosting

Attachment: signature.asc
Description: This is a digitally signed message part.


Current thread: