[SECURITY] CVE-2016-6800 Apache OFBiz blog stored XSS vulnerability

2016-11-28 Thread Jacopo Cappellato
Vendor: The Apache Software Foundation Versions Affected: OFBiz 13.07.* OFBiz 12.04.* OFBiz 11.04.* Description: The default configuration of the OFBiz framework offers a blog functionality. Different users are able to operate blogs which are related to specific parties. In the form field for the

Re: Apache OFBiz blog

2009-04-27 Thread Adam Heath
David E Jones wrote: > > For everyone interested in this: please note that the PMC is currently > discussing how to leverage this resource. The concern is that we don't > want any single person to be able to step up and post something on the > ofbiz blog and imply that it is the opinion and positi

Re: Apache OFBiz blog

2009-04-27 Thread Jacques Le Roux
From: "David E Jones" For everyone interested in this: please note that the PMC is currently discussing how to leverage this resource. The concern is that we don't want any single person to be able to step up and post something on the ofbiz blog and imply that it is the opinion and position of t

Re: Apache OFBiz blog

2009-04-27 Thread David E Jones
For everyone interested in this: please note that the PMC is currently discussing how to leverage this resource. The concern is that we don't want any single person to be able to step up and post something on the ofbiz blog and imply that it is the opinion and position of the project as a

Apache OFBiz blog

2009-04-27 Thread Jacques Le Roux
I have opened a community blog for Apache OFBiz at http://blogs.apache.org/. If you are interested to write articles please ask for a login. Last month, I read a white paper (livre blanc) from a French IT company http://www.smile.fr/ (250 persons, 1st "open source company in France") http://ww