Hi

Another CVE[0] has been issued against bandersnatch.

CVE-2007-6001:

Multiple cross-site scripting (XSS) vulnerabilities in index.php in 
Bandersnatch 0.4 allow remote attackers to inject arbitrary web script or 
HTML via the (1) func or (2) date parameter, or the jid parameter in a (3) 
log or (4) user action, a different vulnerability than CVE-2007-3910.

Please mention the CVE number in the changelog, if you fix it.

Cheers
Steffen

[0]: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6001

Attachment: signature.asc
Description: This is a digitally signed message part.

Reply via email to