oss-sec mailing list archives

Re: CVE request: serendipity before 1.6 backend XSS in karma plugin


From: Hanno Böck <hanno () hboeck de>
Date: Sat, 29 Oct 2011 14:37:48 +0200

Am Fri, 28 Oct 2011 09:04:43 -0600
schrieb Kurt Seifried <kseifried () redhat com>:

Can you please send more details, i.e. which file is responsible/or a
link to a commit fixing this? Thanks.

Commit is here:
https://github.com/s9y/Serendipity/commit/a7861fabd328c3c468f0853355686dd7e39cc4ac#plugins/serendipity_event_karma/serendipity_event_karma.php

Responsible file:
plugins/serendipity_event_karma/serendipity_event_karma.php

-- 
Hanno Böck              mail/jabber: hanno () hboeck de
GPG: BBB51E42           http://www.hboeck.de/

Attachment: signature.asc
Description:


Current thread: