oss-sec mailing list archives

Re: CVE request: Concrete5 XSS vulnerability


From: Korvin Szanto <Korvin () portlandlabs com>
Date: Mon, 5 Jan 2015 09:56:24 -0800

This has been fixed in 5.7.3 for some time
https://github.com/concrete5/concrete5-5.7.0/commit/e3d47d2af88ddef36deaf754ef22f1f39b9b623b

We have a security disclosure program for this so any disclosure
outside of our program is very irresponsible and unprofessional. You
end up with outdated information and leave us unable to fix the issue
in a secure way since we cannot see it until it's brought to our
attention through our disclosure program.

On Fri, Jan 2, 2015 at 11:43 AM, Henri Salo <henri () nerv fi> wrote:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Can you assign CVE identifier for following vulnerability in Concrete5, thanks.

http://seclists.org/bugtraq/2014/Dec/53
http://osvdb.org/115633
http://osvdb.org/115634

ps. there is something wrong with http://www.openwall.com/lists/oss-security/ it
says "an error occurred while processing this directive"

- --
Henri Salo
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAlSm9P4ACgkQXf6hBi6kbk+bfQCgjF/EWeO4Wfs0SUSsq96LwNpE
AWAAn1yKEw9eDAlJ6cQczjzHZ7VGdXUp
=0mVH
-----END PGP SIGNATURE-----


Current thread: