Bug#377299: sitebar: CVE-2006-3320: cross-site scripting

2006-07-28 Thread Martin Schulze
Thijs Kinkhorst wrote: > > > CVE-2006-3320: "Cross-site scripting (XSS) vulnerability in command.php > > in SiteBar 3.3.8 and earlier allows remote attackers to inject arbitrary > > web script or HTML via the command parameter." > > I've already fixed this by NMU in unstable. I've also prepared a

Bug#377299: sitebar: CVE-2006-3320: cross-site scripting

2006-07-28 Thread Thijs Kinkhorst
tags 377299 +patch thanks Hello, > CVE-2006-3320: "Cross-site scripting (XSS) vulnerability in command.php > in SiteBar 3.3.8 and earlier allows remote attackers to inject arbitrary > web script or HTML via the command parameter." I've already fixed this by NMU in unstable. I've also prepared an

Bug#377299: sitebar: CVE-2006-3320: cross-site scripting

2006-07-07 Thread Alec Berryman
Package: sitebar Version: 3.3.8-1 3.2.6-7 Severity: serious Tags: security -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 CVE-2006-3320: "Cross-site scripting (XSS) vulnerability in command.php in SiteBar 3.3.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the comm