Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <Pine.GSO.4.51.0810271924530.1641@faron.mitre.org>
Date: Mon, 27 Oct 2008 19:30:55 -0400 (EDT)
From: "Steven M. Christey" <coley@...us.mitre.org>
To: oss-security@...ts.openwall.com
Subject: XSS in HTML Tidy plugin used in WYSIWYG HTML editors


http://www.securityfocus.com/bid/31908 covers a claimed issue in Kayako
eSupport that probably stems from an XSS in some plugin called HtmlTidy
which is for some WYSIWYG HTML editor called htmlArea.  Quick Google
searches suggest it may be in extensive use in various packages;
squirrelmail and Dragonfly were some of the products I've heard of that
popped up in early results.  I didn't dig deeply though.

This will have a CVE momentarily, but this post should be in the initial
CVE.  Chicken and egg thing basically...

- Steve

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.