Package: lists.debian.org
Severity: wishlist

Hello,

An invalid link to list's  "recent" page, like:
  http://lists.debian.org/debian-foobar/recent
discloses the environment variable of the server.

I doesn't seems to be a problem at this time (except maybe on some
stupid web browsers which ignores the page mime-type=text/plain... in
which case it could be used for script/css injection)

Franklin




-- 
To UNSUBSCRIBE, email to [email protected]
with a subject of "unsubscribe". Trouble? Contact [email protected]

Reply via email to