aboutsummaryrefslogtreecommitdiff
path: root/security
diff options
context:
space:
mode:
authorGreg Larkin <glarkin@FreeBSD.org>2008-12-30 19:16:14 +0000
committerGreg Larkin <glarkin@FreeBSD.org>2008-12-30 19:16:14 +0000
commit6691f735ab0f85ec29722abf05ecf368d9a79ae1 (patch)
tree4750f9eb9f4a70cfb06e9e12c98906723797603f /security
parent5d003674658401e854276157109064bb27614379 (diff)
downloadports-6691f735ab0f85ec29722abf05ecf368d9a79ae1.tar.gz
ports-6691f735ab0f85ec29722abf05ecf368d9a79ae1.zip
Notes
Diffstat (limited to 'security')
-rw-r--r--security/vuxml/vuln.xml36
1 files changed, 36 insertions, 0 deletions
diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml
index 8c00a90f1aa9..70309182bb74 100644
--- a/security/vuxml/vuln.xml
+++ b/security/vuxml/vuln.xml
@@ -34,6 +34,42 @@ Note: Please add new entries to the beginning of this file.
-->
<vuxml xmlns="http://www.vuxml.org/apps/vuxml-1">
+ <vuln vid="f98dea27-d687-11dd-abd1-0050568452ac">
+ <topic>twiki -- multiple vulnerabilities</topic>
+ <affects>
+ <package>
+ <name>twiki</name>
+ <range><lt>4.2.4,1</lt></range>
+ </package>
+ </affects>
+ <description>
+ <body xmlns="http://www.w3.org/1999/xhtml">
+ <p>Marc Schoenefeld and Steve Milner of RedHat SRT and Peter Allor of IBM ISS report:</p>
+ <blockquote cite="http://twiki.org/cgi-bin/view/Codev/TWikiSecurityAlerts#Security_Alerts_of_TWiki_4_2_x_P">
+ <p>XSS vulnerability with URLPARAM variable</p>
+ <p>SEARCH variable allows arbitrary shell command execution</p>
+ </blockquote>
+ </body>
+ </description>
+ <references>
+ <bid>32668</bid>
+ <bid>32669</bid>
+ <cvename>CVE-2008-5304</cvename>
+ <cvename>CVE-2008-5305</cvename>
+ <url>http://secunia.com/advisories/33040</url>
+ <url>http://twiki.org/cgi-bin/view/Codev/SecurityAlert-CVE-2008-5304</url>
+ <url>http://twiki.org/cgi-bin/view/Codev/SecurityAlert-CVE-2008-5305</url>
+ <url>http://www.securitytracker.com/alerts/2008/Dec/1021351.html</url>
+ <url>http://www.securitytracker.com/alerts/2008/Dec/1021352.html</url>
+ <url>https://www.it-isac.org/postings/cyber/alertdetail.php?id=4513</url>
+ <url>http://xforce.iss.net/xforce/xfdb/45293</url>
+ </references>
+ <dates>
+ <discovery>2008-12-05</discovery>
+ <entry>2008-12-30</entry>
+ </dates>
+ </vuln>
+
<vuln vid="8f483746-d45d-11dd-84ec-001fc66e7203">
<topic>roundcube -- remote execution of arbitrary code</topic>
<affects>