oss-sec mailing list archives

Re: CVE-Request -- CMS b2evolution v.5.2.0 -- Reflecting XSS vulnerability in filemanager functionality


From: Henri Salo <henri () nerv fi>
Date: Fri, 16 Jan 2015 10:05:52 +0200

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Thu, Jan 15, 2015 at 04:44:39PM -0500, Daniel Kahn Gillmor wrote:
An attacker could take this signed message, and replay it "From" you
with a changed subject line to try to indicate that you think some other
bug was fixed in some other piece of software, version 5.2.1.

I'll be more careful in the future with automatic PGP signing. :)

- -- 
Henri Salo
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAlS4xmAACgkQXf6hBi6kbk9D0gCfeWLTaJkV5FB+Px9hWQBTbf4l
Q0IAn31Gg1Tve0qNoA7cut3HhGIkf8L+
=v7tU
-----END PGP SIGNATURE-----


Current thread: