Re: [fossil-dev] XSS vulnerability alleged

2018-06-06 Thread Kyle Shannon
On Wed, Jun 6, 2018 at 1:01 PM jungle Boogie wrote: > > On 6 June 2018 at 10:45, Kyle Shannon wrote: > > On Wed, Jun 6, 2018 at 11:44 AM Richard Hipp wrote: > >> > >> On 6/6/18, Kyle Shannon wrote: > >> > Our security team found another XSS, sh

Re: [fossil-dev] XSS vulnerability alleged

2018-06-06 Thread Kyle Shannon
On Wed, Jun 6, 2018 at 11:44 AM Richard Hipp wrote: > > On 6/6/18, Kyle Shannon wrote: > > Our security team found another XSS, shall I forward the link to the list? > > Yes, please > -- > D. Richard Hipp > d...@sqlite.org https://www.fossil-scm.org/index.html/timelin

Re: [fossil-dev] XSS vulnerability alleged

2018-06-06 Thread Kyle Shannon
Our security team found another XSS, shall I forward the link to the list? On Fri, May 12, 2017 at 10:24 AM Richard Hipp wrote: > > On 5/12/17, Kyle Shannon wrote: > > > > Sorry to resurrect an old post, but the site mentioned in the original > > post has disclosed the vu

Re: [fossil-dev] XSS vulnerability alleged

2017-05-12 Thread Kyle Shannon
Hi, On Fri, Jan 15, 2016 at 2:26 PM, Andy Bradford wrote: > Thus said Richard Hipp on Fri, 15 Jan 2016 07:46:17 -0500: > >> I received email alerting me to the following: >> https://www.xssposed.org/incidents/124372/ > > There are free tools that could be run to check their claims... > > These fo

Re: [fossil-dev] XSS vulnerability alleged

2017-05-12 Thread Kyle Shannon
On Fri, May 12, 2017 at 10:24 AM, Richard Hipp wrote: > On 5/12/17, Kyle Shannon wrote: >> >> Sorry to resurrect an old post, but the site mentioned in the original >> post has disclosed the vulnerability. I was just notified by the >> security team at the univer

Re: [fossil-dev] XSS vulnerability alleged

2017-05-12 Thread Kyle Shannon
On Fri, Jan 15, 2016 at 2:26 PM, Andy Bradford wrote: > Thus said Richard Hipp on Fri, 15 Jan 2016 07:46:17 -0500: > >> I received email alerting me to the following: >> https://www.xssposed.org/incidents/124372/ > > There are free tools that could be run to check their claims... > > These folks m