oss-sec mailing list archives

Re: CVE request: phorum < 5.2.15 backend XSS


From: Josh Bressers <bressers () redhat com>
Date: Tue, 18 May 2010 13:16:51 -0400 (EDT)


----- "Hanno Böck" <hanno () hboeck de> wrote:

Release notes:
http://www.facebook.com/note.php?note_id=371190874581


"It also has some security fixes for another less important XSS where a
user could "attack himself" with adding an invalid email address (thanks
to Carlos Ghan for pointing out this issue), see the changelog below for
details. "


Does someone have some additional details for this? I don't see enough
information for me to assign a CVE id.

Thanks

-- 
    JB


Current thread: