Saturday, November 13, 2010

Php: Cross-site Scripting (XSS) Vulnerability

Users of php please be advised of a Cross-site Scripting vulnerability that has been identified.

To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (http://criticalwatch.com/support/security-advisories.aspx)

Amplify’d from www.criticalwatch.com
MDVSA-2010:224: [MDVSA-2010:224] php Cross-site Scripting
Problem Description:



A vulnerability was discovered and corrected in php:



A flaw in ext/xml/xml.c could cause a cross-site scripting (XSS)

vulnerability (CVE-2010-3870).



Packages for 2009.0 are provided as of the Extended Maintenance

Program. Please visit this link to learn more:

http://store.mandriva.com/product_info.php?cPath=149&products_id=490



The updated packages have been patched to correct these issues.
Read more at www.criticalwatch.com
 

No comments:

Post a Comment