On Jan 15, 2008 12:16 AM, Tom Hughes <[EMAIL PROTECTED]> wrote: > In message <[EMAIL PROTECTED]> > Callum Noble <[EMAIL PROTECTED]> wrote: > > > I notice that the message sending section of the openstreetmap.org site > > is vulnerable to type 2 XSS attacks. > > Well thank you for announcing that on a public mailing list. Do you > not think an email to webmaster might have been more sensible?
Easy Tom, don't flame the guy. The last time anyone mentioned an XSS problem with our site, SteveC himself sent it to dev, asking the reporter to log it on trac. How much more public can you get? http://lists.openstreetmap.org/pipermail/dev/2007-July/005618.html Perhaps we should set up a security@ alias, and make it obvious on our website (perhaps on http://wiki.openstreetmap.org/index.php/Contact at least) as to how you can contact the admins privately with security issues. Cheers, Andy _______________________________________________ dev mailing list [email protected] http://lists.openstreetmap.org/cgi-bin/mailman/listinfo/dev

