[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <alpine.LNX.2.00.1008141853460.17744@forced.attrition.org>
Date: Sat, 14 Aug 2010 18:58:41 -0500 (CDT)
From: security curmudgeon <jericho@...rition.org>
To: advisory@...ridge.ch
Cc: bugtraq@...urityfocus.com
Subject: Re: XSS vulnerability in WebPress
: Product: WebPress
: Vendor: YWP ( http://www.goywp.com/ )
: Vulnerable Version: Current at 01.07.2010 and Probably Prior Versions
The vendor web page has a demo feature, that is powered by "YWP 13.00.04".
Creating a demo via their site, the changelog shows "05.05.2010 - Released
version 13.00.04". Your version of 01.07.2010 appears to be something you
designated, based on the date you notified the vendor.
It appears this is a site specific issue in YWP (http://www.goywp.com/).
Can you confirm this is a downloadable product and the version affected?
Powered by blists - more mailing lists