[CVE-2012-3373] Apache Wicket XSS vulnerability via manipulated URL parameter

2012-09-06 Thread Carl-Eric Menzel
Severity: Important Vendor: The Apache Software Foundation Versions Affected: Apache Wicket 1.4.x and 1.5.x Description: https://wicket.apache.org/2012/09/06/cve-2012-3373.html It is possible to inject JavaScript statements into an ajax link by adding an encoded null byte to a URL pointing to a

Re: Apache Wicket 6 in the news

2012-09-06 Thread Andrea Del Bene
Good work indeed! You have done an impressive job promoting this release! Thanks to the awesome support of press@ (THX Sally!) we have some great coverage of our 6.0 release: ASF Bowls Apache Wicket 6.0 At Open Sourcers http://www.techweekeurope.co.uk/news/asf-apache-wicket-6-0-91604 Hitting