Saturday, October 2, 2010

Mako: cross-site scripting vulnerability

Users of Mako please be advised of a cross-site scripting vulnerability that has been identified.

To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (http://criticalwatch.com/support/security-advisories.aspx)

Amplify’d from www.criticalwatch.com
USN-996-1: [USN-996-1] Mako cross-site scripting vulnerability
Details follow:



It was discovered that Mako incorrectly filtered single-quote characters

when performing html filtering. An attacker could utilize this to perform

cross-site scripting attacks.


Read more at www.criticalwatch.com
 

No comments:

Post a Comment