Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <20120706222139.GI1678@suse.de>
Date: Sat, 7 Jul 2012 00:21:40 +0200
From: Marcus Meissner <meissner@...e.de>
To: OSS Security List <oss-security@...ts.openwall.com>
Subject: CVE Request: XSS in a Mono System.web error page 

Hi,

A Nessus scan of a Novell product using Mono Web revealed a XSS attack
in the Mono System.Web library.

The Mono team commited a fix to their GIT.

References:
	https://bugzilla.novell.com/show_bug.cgi?id=769799
	https://github.com/mono/mono/commit/d16d4623edb210635bec3ca3786481b82cde25a2

The XSS is in the error popup of the "Forbidden extension" filter method,
which filters out e.g. ".dll" files.

Ciao, Marcus

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.