oss-sec mailing list archives
Re: CVE-Request -- CMS b2evolution v.5.2.0 -- Reflecting XSS vulnerability in filemanager functionality
From: Henri Salo <henri () nerv fi>
Date: Fri, 16 Jan 2015 10:05:52 +0200
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Thu, Jan 15, 2015 at 04:44:39PM -0500, Daniel Kahn Gillmor wrote:
An attacker could take this signed message, and replay it "From" you with a changed subject line to try to indicate that you think some other bug was fixed in some other piece of software, version 5.2.1.
I'll be more careful in the future with automatic PGP signing. :) - -- Henri Salo -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAlS4xmAACgkQXf6hBi6kbk9D0gCfeWLTaJkV5FB+Px9hWQBTbf4l Q0IAn31Gg1Tve0qNoA7cut3HhGIkf8L+ =v7tU -----END PGP SIGNATURE-----
Current thread:
- CVE-Request -- CMS b2evolution v.5.2.0 -- Reflecting XSS vulnerability in filemanager functionality Steffen Rösemann (Jan 13)
- Re: CVE-Request -- CMS b2evolution v.5.2.0 -- Reflecting XSS vulnerability in filemanager functionality Henri Salo (Jan 14)
- Re: CVE-Request -- CMS b2evolution v.5.2.0 -- Reflecting XSS vulnerability in filemanager functionality Daniel Kahn Gillmor (Jan 15)
- Re: CVE-Request -- CMS b2evolution v.5.2.0 -- Reflecting XSS vulnerability in filemanager functionality Hanno Böck (Jan 15)
- Re: CVE-Request -- CMS b2evolution v.5.2.0 -- Reflecting XSS vulnerability in filemanager functionality Henri Salo (Jan 16)
- Re: CVE-Request -- CMS b2evolution v.5.2.0 -- Reflecting XSS vulnerability in filemanager functionality Daniel Kahn Gillmor (Jan 15)
- Re: CVE-Request -- CMS b2evolution v.5.2.0 -- Reflecting XSS vulnerability in filemanager functionality cve-assign (Feb 12)
- Re: CVE-Request -- CMS b2evolution v.5.2.0 -- Reflecting XSS vulnerability in filemanager functionality Henri Salo (Jan 14)