lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Date: Sat, 14 Aug 2010 20:27:50 -0500 (CDT) From: security curmudgeon <jericho@...rition.org> To: advisory@...ridge.ch Cc: bugtraq@...urityfocus.com Subject: Re: XSS vulnerability in Theeta CMS : Vulnerability ID: HTB22489 : Reference: http://www.htbridge.ch/advisory/xss_vulnerability_in_theeta_cms_2.html : Vendor: MN Tech Solutions : Vulnerable Version: 0.0 : The vulnerability exists due to failure in the "forum.php" script to : properly sanitize user-supplied input in "forum" variable. Successful : exploitation of this vulnerability could result in a compromise of the : application, theft of cookie-based authentication credentials, : disclosure or modification of sensitive data. Disclosed on 2009-12-01 by c0dy[at]r00tDefaced.net, and assigned CVE-2009-4782.
Powered by blists - more mailing lists