oss-security February 2012 archive
Main Archive Page > Month Archives  > oss-security archives
oss-security: [oss-security] Re: CVE Status Clarification / Requ

[oss-security] Re: CVE Status Clarification / Request -- kadu: Stored XSS by parsing contact's status and sms messages in history

From: Mateusz Goik <mateusz.goik_at_nospam>
Date: Mon Feb 27 2012 - 16:11:32 GMT
To: Rafał Malinowski <rafal.przemyslaw.malinowski@gmail.com>

Hi,

I would add it is possible - read / create files on users hdd. (using
the method - GET / PUT)
Tested on Backtrack 5 r1 (kadu 0.10.0 - compiled from source).

Mateusz Goik