Re: [Full-disclosure] Drupal core XSS vulnerability

2013-08-14 Thread Greg Knaddison
Thanks to Justin for identifying and describing this issue. With a little more detail inline. On Wed, Aug 14, 2013 at 7:33 AM, Justin C. Klein Keane wrote: > Mitigating factors: > - --- > In order to inject arbitrary script malicious attackers must have the > ability to manipula

Re: [Full-disclosure] WordPress Authenticated File Upload Authorisation Bypass

2012-06-21 Thread Greg Knaddison
On Wed, Jun 20, 2012 at 8:04 PM, Denis Andzakovic < denis.andzako...@security-assessment.com> wrote: > Exploitation of this vulnerability requires a malicious user with > access to the admin panel to use the > "/wp-admin/plugin-install.php?tab=upload" page to upload a malicious > file. That tool

Re: [Full-disclosure] [Security-news] SA-CONTRIB-2012-051 - Activity - Multiple Vulnerablities

2012-03-29 Thread Greg Knaddison
I should note that Justin was a reporter of the issue to the Drupal Security Team. When writing the advisory he was mistakenly excluded. That's been corrected in the html version of this advisory http://drupal.org/node/1506562 On Wed, Mar 28, 2012 at 4:40 PM, Justin C. Klein Keane wrote: > Explo

Re: [Full-disclosure] [Security-news] SA-CONTRIB-2012-040 - CKEditor and FCKeditor - multiple XSS, arbitrary code execution

2012-03-16 Thread Greg Knaddison
nding to this > public mailing list. > > > > Best regards, > MaXe > > > On Thu, 15 Mar 2012 07:57:17 -0600, Greg Knaddison > wrote: >> Hello MaXe, >> >> Thanks for the feedback. >> >> Our security advisories are meant to be a littl

Re: [Full-disclosure] [Security-news] SA-CONTRIB-2012-040 - CKEditor and FCKeditor - multiple XSS, arbitrary code execution

2012-03-15 Thread Greg Knaddison
Hello MaXe, Thanks for the feedback. Our security advisories are meant to be a little opaque and do not include a POC, so I can understand how these two issues could be confusing: they both include XSS in something named (F)CKEditor. However this issue is quite different from the one you identif

Re: [Full-disclosure] posting xss notifications in sites vs software packages

2012-02-08 Thread Greg Knaddison
On Tue, Feb 7, 2012 at 4:18 PM, b wrote: > What is the point of posting notifications of XSS vulnerabilities in > specific web sites instead of alerts of xss vulns in specific software > packages? I think there are at least 2 reasons: 1. We have pretty good data about bugs in published software

Re: [Full-disclosure] Vulnerability in multiple themes for Drupal

2011-10-04 Thread Greg Knaddison
making an announcement about them. Regards, Greg Knaddison, a member of the Drupal Security Team speaking my own behalf -- Director Security Services Skype: greg.knaddison | http://twitter.com/greggles | http://acquia.com ___ Full-Disclosure - We