[27236] in bugtraq
Postnuke XSS patch
daemon@ATHENA.MIT.EDU (Mark Grimes)
Tue Oct 1 16:45:32 2002
From: Mark Grimes <mark@stateful.net>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Message-ID: <15769.34877.867622.252501@stateful.net>
Date: Tue, 1 Oct 2002 04:34:21 -0700
To: bugtraq@securityfocus.com
Reply-To: mark@stateful.net
[For Immediate Release]
The PostNuke Security Officer has updated the CVS version of Postnuke and a
patch will be made available today to fix the outstanding issue shown here
http://marc.theaimsgroup.com/?l=bugtraq&m=103306696427569&w=2
It is apparent that the Postnuke developers reviewed the material suggested
vulnerable and deemed it worthy of a patch. Please refer to their website for
patch availability, as I was not provided a specific URL to point you to.
--
Mark Grimes <mark@stateful.net>
Stateful Labs