Re: [oss-security] Case YVS Image Gallery

2012-03-19 Thread Kurt Seifried
On 02/27/2012 02:39 PM, Henri Salo wrote: On Mon, Feb 27, 2012 at 09:31:52AM -0700, Kurt Seifried wrote: If you make a list of issues (e.g. XSS, CSRF, etc) with the code examples I can assign the various blocks of issues CVEs. 1. ./administration/install.php opens ../functions/db_connect.php

Re: [oss-security] Case YVS Image Gallery

2012-02-28 Thread Henri Salo
On Mon, Feb 27, 2012 at 09:31:52AM -0700, Kurt Seifried wrote: If you make a list of issues (e.g. XSS, CSRF, etc) with the code examples I can assign the various blocks of issues CVEs. 1. ./administration/install.php opens ../functions/db_connect.php and writes to file without input validation