Re: gnatsweb/755: XSS vuln.

Chad Walstrom <[email protected]> Thu, 14 Jun 2007 11:25:20 -0500
Newsgroups gmane.comp.bug-tracking.gnats.general
Message-ID <[email protected]>
Unfortunately, Gnatsweb 4.0 doesn't do much for parameter or cookie
input validation and scrubbing.  Adding that functionality would be a
welcome addition.  Yngve is the person to go for this, as I do not
have CVS access or project access to Gnatsweb, just GNATS.  I suspect
that the database parameter isn't the only vulnerability.

-- 
Chad Walstrom <[email protected]>           http://www.wookimus.net/
           assert(expired(knowledge)); /* core dump */