[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <86vfqkmqbo.fsf@home.nest.cx>
From: greg-fulldisclosure at nest.cx (Gregory Steuck)
Subject: Caucho Resin 2.x - Cross Site Scripting
>>>>> "jelmer" == jelmer <jkuperus@...net.nl> writes:
jelmer> Donny, These are in the example applications, which any sane
jelmer> admin should disable right away, much like caucho-status
jelmer> These are basic procedures in setting up a server.
Yes, but is it not extremely lame of the vendor to ship samples with
XSS vulnerabilities?
Powered by blists - more mailing lists