Package: sitebar
Severity: important
Tags: security

Hi

The following CVE[0] about multiple cross-site scripting vulnerabilities
has been issued against sitebar.

CVE-2007-5692:

Multiple cross-site scripting (XSS) vulnerabilities in SiteBar 3.3.8
allow remote attackers to inject arbitrary web script or HTML via (1)
the lang parameter to integrator.php; (2) the token parameter in a New
Password action, (3) the nid_acl parameter in a Folder Properties
action, or (4) the uid parameter in a Modify User action to command.php;
or (5) the target parameter to index.php, different vectors than
CVE-2006-3320. 


Please remember to mention the CVE number in the changelog, when you fix
this bug.
Thanks for your efforts.

Cheers
Steffen

[0]: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5692



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to