Bug#395099: CVE-2006-5451: several XSS vulnerabilities in torrentflux

2006-10-28 Thread Cameron Dale
tags 395099 + pending thanks Thanks again for the report. I've updated the code using patches based on the beta release from the next upstream upgrade. This should be uploaded very soon. Cameron -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EM

Bug#395099: CVE-2006-5451: several XSS vulnerabilities in torrentflux

2006-10-27 Thread Cameron Dale
severity 395099 grave tags 395099 + security thanks Thanks for the report, I hadn't seen these yet. I upgraded the severity as it is a security problem. I'm working on a fix now. Here is the CVE for this: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5451 Cameron -- To UNSUBSCRIBE,

Bug#395099: CVE-2006-5451: several XSS vulnerabilities in torrentflux

2006-10-24 Thread Stefan Fritsch
package: torrentflux severity: important tags: security Several vulnerabilities have been found in torrentflux: Multiple cross-site scripting (XSS) vulnerabilities in TorrentFlux 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) action, (2) file, and (3) users array va