in 0.7.4:
The blog entry title field seems prone to cross site scripting (XSS)
attacks.
The blog/comment body text seems prone to XSS as well.
In the index.php script, the postid variable seems prone to SQL injection
attacks.
jericho+bblog@attrition.org
Nobody/Anonymous ( nobody ) - 2005-04-23 21:30
5
Open
None
Nobody/Anonymous
None
0.7-cvs
Public
|
Date: 2005-05-30 14:03 Logged In: YES |
Copyright © 2010 Geeknet, Inc. All rights reserved. Terms of Use