oss-sec mailing list archives

Re: CVE Status Clarification / Request -- kadu: Stored XSS by parsing contact's status and sms messages in history


From: Mateusz Goik <mateusz.goik () aliantsoft pl>
Date: Mon, 27 Feb 2012 17:13:32 +0100

Sorry. Tested on kadu 0.11.0..

Mateusz Goik.

On 02/27/2012 05:11 PM, Mateusz Goik wrote:
Hi,

I would add it is possible - read / create files on users hdd. (using
the method - GET / PUT)
Tested on Backtrack 5 r1 (kadu 0.10.0 - compiled from source).

Mateusz Goik


Current thread: