[27236] in bugtraq

home help back first fref pref prev next nref lref last post

Postnuke XSS patch

daemon@ATHENA.MIT.EDU (Mark Grimes)
Tue Oct 1 16:45:32 2002

From: Mark Grimes <mark@stateful.net>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Message-ID: <15769.34877.867622.252501@stateful.net>
Date: Tue, 1 Oct 2002 04:34:21 -0700
To: bugtraq@securityfocus.com
Reply-To: mark@stateful.net


[For Immediate Release]

The PostNuke Security Officer has updated the CVS version of Postnuke and a
patch will be made available today to fix the outstanding issue shown here
http://marc.theaimsgroup.com/?l=bugtraq&m=103306696427569&w=2

It is apparent that the Postnuke developers reviewed the material suggested
vulnerable and deemed it worthy of a patch.  Please refer to their website for
patch availability, as I was not provided a specific URL to point you to.

--
Mark Grimes <mark@stateful.net>
Stateful Labs

home help back first fref pref prev next nref lref last post