Hello,

The package in debian is 1.5.2 and doesn't contain GetURLArguments function

Cheers

Christian

Giuseppe Iuculano a écrit :
> Package: libphp-jpgraph
> Severity: serious
> Tags: security
> 
> 
> Hi,
> the following CVE (Common Vulnerabilities & Exposures) id was
> published for libphp-jpgraph.
> 
> CVE-2009-4422[0]:
> | Multiple cross-site scripting (XSS) vulnerabilities in the
> | GetURLArguments function in jpgraph.php in Aditus Consulting JpGraph
> | 3.0.6 allow remote attackers to inject arbitrary web script or HTML
> | via a key to csim_in_html_ex1.php, and other unspecified vectors.
> 
> If you fix the vulnerability please also make sure to include the
> CVE id in your changelog entry.
> 
> For further information see:
> 
> [0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4422
>     http://security-tracker.debian.org/tracker/CVE-2009-4422
> 
> 



-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Reply via email to