Full Disclosure mailing list archives
Re: i hate it when some one beats me to a bug
From: Reed Loden <reed () reedloden com>
Date: Wed, 15 Dec 2010 09:59:51 -0800
On Thu, 16 Dec 2010 02:26:57 +1100 dave b <db.pub.mail () gmail com> wrote:
I hate it when some one beats me to a bug report. https://addons.mozilla.org/en-US/firefox/user/5578717/ (this example will only work against firefox). The xss occurs due to no filtering / escaping the display name attribute for a user.
Sorry, Dave, that somebody "beat you to it", but we definitely appreciate you taking the time to report the problem to us. Having community support in finding vulnerabilities such as the one you discovered is great to making sure users stay safe on the Web. We've just pushed out a fix for it, so the issue should now be resolved. Thanks for taking part in Mozilla's new Web Application Security Bug Bounty Program[0] (such a mouthful to say or type). Let us know if you discover any more issues, and hopefully, you'll be the first one that time. :) Have a wonderful rest of the week! ~reed Mozilla Security Group [0] http://blog.mozilla.com/security/2010/12/14/adding-web-applications-to-the-security-bug-bounty-program/ -- Reed Loden reed () reedloden com _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- i hate it when some one beats me to a bug dave b (Dec 15)
- Re: i hate it when some one beats me to a bug Peter Besenbruch (Dec 15)
- Re: i hate it when some one beats me to a bug Benji (Dec 15)
- Re: i hate it when some one beats me to a bug Reed Loden (Dec 15)
- Re: i hate it when some one beats me to a bug dave b (Dec 15)
- Re: i hate it when some one beats me to a bug Peter Besenbruch (Dec 15)