LWN.net Logo

kronolith2: cross-site scripting

Package(s):kronolith2 CVE #(s):CVE-2008-1974
Created:April 28, 2008 Updated:June 11, 2008
Description:

From the Debian advisory:

"The-0utl4w" discovered that the Kronolith, calendar component for the Horde Framework, didn't properly sanitise URL input, leading to a cross-site scripting vulnerability in the add event screen.

Alerts:
Debian DSA-1560-1 2008-04-28
Fedora FEDORA-2008-3543 2008-06-11
Fedora FEDORA-2008-3460 2008-06-11

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds
Powered by Rackspace Managed Hosting.