Re: [Full-disclosure] Drupal Help Injection Module XSS Vulnerability

2010-02-27 Thread Mori Sugimoto
This module is still in alpha and not considered suitable for any production environment. Drupal Security Team does not deal with vulnerability reports that are related to major releases or release candidates. Instead we encourage reporters to contact the module maintainers and fix any issue in

Re: [Full-disclosure] Drupal Help Injection Module XSS Vulnerability

2010-02-27 Thread Mori Sugimoto
Correction: Drupal Security Team _only_ deals with vulnerability reports that are related to major releases or release candidates. Mori Sugimoto Drupal Security Team On 27/02/2010 23:49, Mori Sugimoto wrote: This module is still in alpha and not considered suitable for any production

[Full-disclosure] Drupal Help Injection Module XSS Vulnerability

2010-02-17 Thread Justin C. Klein Keane
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 The full text of this advisory can also be found at http://www.madirish.net/?article=448 Description of Vulnerability: - - Drupal (http://drupal.org) is a robust content management system (CMS) written in PHP and MySQL