SlashcodeSlash Open Source ProjectFull Disclosure and Patches on CVS Vulnerability- December 20, 2004 The "security issue" described on the morning of Dec. 15th is actually two separate and unrelated cross-site scripting (XSS) bugs. We're disclosing all of what we know about them at this point to allow site admins to patch sites which cannot reasonably be upgraded to the latest, fixed version of the code, the Dec. 8th build R_2_5_0_41. Both of these issues were found by Michael Krax who we understand will be publishing something about them shortly. Again, we thank Mr. Krax for responsibly...http://www.slashcode.com/article.pl?sid=04/12/20/1946225&from=rss |