Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: SQL-injection, XSS in OSSIM (Open Source Security Information Management) Feb 22 2008 07:50AM
Dominique Karg (dk ossim net)
Hello,

I can confirm this affecting earlier versions as well, the XSS has
been fixed some months ago, the SQL Injection (and others) were caused
by a failure in the "punctuation" validation regexp. Just fixed that
one as well as some others.

We're going to release a fixed version asap after ...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus