oss-sec mailing list archives

Re: CVE-request: Webcalendar 1.2.4 location XSS


From: Eitan Adler <lists () eitanadler com>
Date: Sat, 11 Feb 2012 23:04:19 -0500

On Sat, Feb 11, 2012 at 11:41 AM, Henri Salo <henri () nerv fi> wrote:
This seems to be missing 2012 CVE.

Original report: http://seclists.org/bugtraq/2012/Jan/128
Project page: https://sourceforge.net/projects/webcalendar/
Version affected: 1.2.4 (the newest)

So far as I could see the newest version is 1.2.3
(http://sourceforge.net/projects/webcalendar/?source=directory and
http://www.k5n.us/webcalendar.php?topic=News don't list 1.2.4)

-- 
Eitan Adler


Current thread: