oss-sec mailing list archives
Re: CVE request: moodle xss in < 1.8.5
From: "Steven M. Christey" <coley () linus mitre org>
Date: Tue, 8 Jul 2008 13:42:21 -0400 (EDT)
On Tue, 8 Jul 2008, Hanno [utf-8] B??ck wrote:
Am Sonntag 06 Juli 2008 schrieb Nico Golde:Hi Hanno, * Hanno B??ck <hanno () hboeck de> [2008-07-06 19:04]:http://docs.moodle.org/en/Release_Notes#Moodle_1.8.5 * KSES related XSS security vulnerability fixedThis should be CVE-2008-1502:
This looks like a shared codebase relationship, which would usually involve the same CVE. If the issue is really in KSES, then CVE-2008-1502 would need to be updated to reflect that it affects KSES as used in egroupWare, Moodle, and others. Can anyone clarify? - Steve
Current thread:
- CVE request: moodle xss in < 1.8.5 Hanno Böck (Jul 06)
- Re: CVE request: moodle xss in < 1.8.5 Nico Golde (Jul 06)
- Re: CVE request: moodle xss in < 1.8.5 Hanno Böck (Jul 08)
- Re: CVE request: moodle xss in < 1.8.5 Nico Golde (Jul 08)
- Re: CVE request: moodle xss in < 1.8.5 Steven M. Christey (Jul 08)
- Re: CVE request: moodle xss in < 1.8.5 Nico Golde (Jul 08)
- Re: CVE request: moodle xss in < 1.8.5 Nico Golde (Jul 11)
- Re: CVE request: moodle xss in < 1.8.5 Hanno Böck (Jul 08)
- Re: CVE request: moodle xss in < 1.8.5 Nico Golde (Jul 06)