| New User, Welcome! Login |
Re: XSS vulnerability in WebPress
| From: |
security curmudgeon <jericho attrition org> |
| To: |
advisory htbridge ch |
| Cc: |
bugtraq securityfocus com |
| Subject: |
Re: XSS vulnerability in WebPress |
| Date: |
Sat - Aug 14, 2010 04:41 PM |
: Product: WebPress
: Vendor: YWP ( http://www.goywp.com/ )
: Vulnerable Version: Current at 01.07.2010 and Probably Prior Versions
The vendor web page has a demo feature, that is powered by "YWP 13.00.04".
Creating a demo via their site, the changelog shows "05.05.2010 - Released
version 13.00.04". Your version of 01.07.2010 appears to be something you
designated, based on the date you notified the vendor.
It appears this is a site specific issue in YWP (http://www.goywp.com/).
Can you confirm this is a downloadable product and the version affected?
|
|
|
Copyright © 1995-2012 LinuxRocket.net. All rights reserved.
Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!