oss-sec mailing list archives

Re: CVE request: XSS in piwik before 1.9


From: Solar Designer <solar () openwall com>
Date: Tue, 23 Oct 2012 06:50:33 +0400

Kurt, all -

On Tue, Oct 23, 2012 at 01:48:55AM +0000, Kurt Seifried wrote:
[...]
Powered by UserVoice.

I am sorry for letting a spoofed bounce "from Kurt" through to the list.
Apparently, some list member is using UserVoice, whatever that is, and
it has produced this spoofed bounce (really weird).  We'll try to be
more careful in rejecting such bounces going forward.

I now see that Kurt's actual message, with proper quoting and From
address, was already on the list (and this is what triggered the bounce,
presumably).

Alexander


Current thread: