Re: [Full-disclosure] Transmission BitTorrent XSS Vulnerability

2012-07-28 Thread Tavis Ormandy
Tavis Ormandy wrote: > Justin Klein Keane wrote: > > > Impact - -- Clients loading a maliciously crafted .torrent file into > > Transmission and viewing the web client could be subject to arbitrary > > script injection, allowing an attacker to run arbitrary code in the > > context of the vi

Re: [Full-disclosure] Transmission BitTorrent XSS Vulnerability

2012-07-28 Thread Tavis Ormandy
Justin Klein Keane wrote: > Impact - -- Clients loading a maliciously crafted .torrent file into > Transmission and viewing the web client could be subject to arbitrary > script injection, allowing an attacker to run arbitrary code in the > context of the victim's web browser. This could lea

[Full-disclosure] Transmission BitTorrent XSS Vulnerability

2012-07-26 Thread Justin Klein Keane
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Vulnerability Report Author: Justin C. Klein Keane Reported: July 19, 2012 CVE-2012-4037 Description of Vulnerability: - - Transmission (http://www.transmissionbt.com) is a popular, cross platform, open source BitTorrent