Re: gnatsweb/755: XSS vuln.
Chad Walstrom <[email protected]> Thu, 14 Jun 2007 11:25:20 -0500
| Newsgroups | gmane.comp.bug-tracking.gnats.general |
|---|---|
| Message-ID | <[email protected]> |
Unfortunately, Gnatsweb 4.0 doesn't do much for parameter or cookie input validation and scrubbing. Adding that functionality would be a welcome addition. Yngve is the person to go for this, as I do not have CVS access or project access to Gnatsweb, just GNATS. I suspect that the database parameter isn't the only vulnerability. -- Chad Walstrom <[email protected]> http://www.wookimus.net/ assert(expired(knowledge)); /* core dump */