Re: XSS vuln in cvsweb

2019-03-15 Thread Marc Espie
On Fri, Mar 15, 2019 at 12:16:06PM -, Stuart Henderson wrote: > On 2019-03-15, Peter J. Philipp wrote: > > Hi all, > > > > I have been notified by a wonderful security researcher that my site was > > vulnerable to XSS attacks. The first one was on software I wrote, and the > > second one was

Re: XSS vuln in cvsweb

2019-03-15 Thread Stuart Henderson
On 2019-03-15, Peter J. Philipp wrote: > Hi all, > > I have been notified by a wonderful security researcher that my site was > vulnerable to XSS attacks. The first one was on software I wrote, and the > second one was on software I got from OpenBSD ports. Not sure if I should > be writing this

XSS vuln in cvsweb

2019-03-15 Thread Peter J. Philipp
Hi all, I have been notified by a wonderful security researcher that my site was vulnerable to XSS attacks. The first one was on software I wrote, and the second one was on software I got from OpenBSD ports. Not sure if I should be writing this to the ports mailing list though. I have written