|
Message-ID: <20120706222139.GI1678@suse.de> Date: Sat, 7 Jul 2012 00:21:40 +0200 From: Marcus Meissner <meissner@...e.de> To: OSS Security List <oss-security@...ts.openwall.com> Subject: CVE Request: XSS in a Mono System.web error page Hi, A Nessus scan of a Novell product using Mono Web revealed a XSS attack in the Mono System.Web library. The Mono team commited a fix to their GIT. References: https://bugzilla.novell.com/show_bug.cgi?id=769799 https://github.com/mono/mono/commit/d16d4623edb210635bec3ca3786481b82cde25a2 The XSS is in the error popup of the "Forbidden extension" filter method, which filters out e.g. ".dll" files. Ciao, Marcus
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.