|
|
| |
|
| |
slash: SQL injection, cross-site scripting
| Package(s): | slash |
CVE #(s): | CVE-2008-2231
CVE-2008-2553
|
| Created: | September 2, 2008 |
Updated: | September 3, 2008 |
| Description: |
From the Debian alert: It has been discovered that Slash, the Slashdot Like Automated Storytelling Homepage suffers from two vulnerabilities related to
insufficient input sanitation, leading to execution of SQL commands
(CVE-2008-2231) and cross-site scripting (CVE-2008-2553).
|
| Alerts: |
|
( Log in to post comments)
|
|
|