oss-sec mailing list archives

CVE request: serendipity freetag plugin before 3.30 and probably others


From: Hanno Böck <hanno () hboeck de>
Date: Sun, 9 Oct 2011 01:14:22 +0200

XSS in the tagcloud generation flash in serendipity freetag before 3.30:
http://blog.s9y.org/archives/234-Security-fix-for-flash-based-cloud-in-Freetag-plugin.html

The linked vulnerability report indicates that this flash code is also
used by other software, e.g. the wp cumulus plugin:
http://websecurity.com.ua/5356/

Though my ukrainian isn't that good ;-)

Please assign cve.

-- 
Hanno Böck              mail/jabber: hanno () hboeck de
GPG: BBB51E42           http://www.hboeck.de/

Attachment: signature.asc
Description:


Current thread: