Re: XSS vulnerability in debian.org

2010-01-05 Thread Don Armstrong
On Wed, 06 Jan 2010, Holger Levsen wrote: > ow...@bugs.debian.org is the right address for such reports. > > On Mittwoch, 6. Januar 2010, David Shaw wrote: > > While browsing debian.org today, I noticed that some of the fields > > were not correctly sanitized, leading to a cross-site scripting > >

Re: XSS vulnerability in debian.org

2010-01-05 Thread Holger Levsen
Hi David, ow...@bugs.debian.org is the right address for such reports. On Mittwoch, 6. Januar 2010, David Shaw wrote: > Hello, > > My name is David Shaw, and I am a security engineer with Redspin, Inc. > > While browsing debian.org today, I noticed that some of the fields were not > correctly san

XSS vulnerability in debian.org

2010-01-05 Thread David Shaw
Hello, My name is David Shaw, and I am a security engineer with Redspin, Inc. While browsing debian.org today, I noticed that some of the fields were not correctly sanitized, leading to a cross-site scripting vulnerability. The URL to verify this vulnerability (with an XSS popup) is: http://bug