(no subject)

2006-01-06 Thread KSMUSICINC
what are the pick6lotto for 12/26/05

Bug#346255: Javascript and HTML injection on http://qa.debian.org/developer.php

2006-01-06 Thread Christoph Berg
Re: Thijs Kinkhorst in <[EMAIL PROTECTED]> > I think you might have broken something, since viewing my own DDPO doesn't > work anymore: > http://qa.debian.org/developer.php?login=kink%40squirrelmail.org&comaint=yes Confirmed. @ is not a valid character at the moment. I can't fix it before Sunday e

Bug#346255: Javascript and HTML injection on http://qa.debian.org/developer.php

2006-01-06 Thread Thijs Kinkhorst
> [0] [EMAIL PROTECTED]:~/qa/wml 1j $cvs ci -m 'filter input for sanity (Closes: > #346255)' developer.wml < Checking in developer.wml; > /org/cvs.debian.org/cvs/qa/wml/developer.wml,v <-- developer.wml > new revision: 1.141; previous revision: 1.140 > done I think you might have broken somethin

Bug#346255: Javascript and HTML injection on http://qa.debian.org/developer.php

2006-01-06 Thread Christoph Berg
severity 346255 grave thanks Re: Frederik Reiss in <[EMAIL PROTECTED]> > Severity: critical > Justification: root security hole Bullshit. Downgrading. Christoph -- [EMAIL PROTECTED] | http://www.df7cb.de/ signature.asc Description: Digital signature

Bug#346255: Javascript and HTML injection on http://qa.debian.org/developer.php

2006-01-06 Thread Thijs Kinkhorst
severity 346255 minor thanks Hello Frederik, On Fri, January 6, 2006 18:18, Frederik Reiss wrote: > on http://qa.debian.org/developer.php it is possible to inject javascript > and html tags: > > http://qa.debian.org/developer.php?excuse=%3Cscript%20type=text/javascript%3Ealert(this)%3C/script%3E

Bug#346255: Javascript and HTML injection on http://qa.debian.org/developer.php

2006-01-06 Thread Frederik Reiss
Package: qa.debian.org Severity: critical Tags: security Justification: root security hole on http://qa.debian.org/developer.php it is possible to inject javascript and html tags: http://qa.debian.org/developer.php?excuse=%3Cscript%20type=text/javascript%3Ealert(this)%3C/script%3E -- System In