Tuesday, August 3, 2010

Debian Security Advisory : New moin packages fix cross-site scripting vulnerability

Users of Debian Security Advisory please be advised of a(New moin packages fix cross-site scripting vulnerability that has been identified.

To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (http://criticalwatch.com/support/security-advisories.aspx)

Amplify’d from www.criticalwatch.com
DSA 2083-1: DSA 2083-1 New moin packages fix cross-site scripting
Debian Security Advisory
It was discovered that moin, a python clone of WikiWiki, does not sufficiently

sanitize parameters when passing them to the add_msg function. This allows a

remote attackers to conduct cross-site scripting (XSS) attacks for example

via the template parameter.Read more at www.criticalwatch.com
 

No comments:

Post a Comment