Bugtraq mailing list archives
Re: XSS vulnerability in WebPress
From: security curmudgeon <jericho () attrition org>
Date: Sat, 14 Aug 2010 18:58:41 -0500 (CDT)
: Product: WebPress : Vendor: YWP ( http://www.goywp.com/ ) : Vulnerable Version: Current at 01.07.2010 and Probably Prior Versions The vendor web page has a demo feature, that is powered by "YWP 13.00.04". Creating a demo via their site, the changelog shows "05.05.2010 - Released version 13.00.04". Your version of 01.07.2010 appears to be something you designated, based on the date you notified the vendor. It appears this is a site specific issue in YWP (http://www.goywp.com/). Can you confirm this is a downloadable product and the version affected?
Current thread:
- Re: XSS vulnerability in WebPress security curmudgeon (Aug 16)