[<prev] [next>] [<thread-prev] [thread-next>] [month] [year] [list]
Date: Tue, 8 Jul 2008 13:21:06 +0200
From: Hanno Böck <hanno@...eck.de>
To: oss-security@...ts.openwall.com
Subject: Re: CVE request: moodle xss in < 1.8.5
Am Sonntag 06 Juli 2008 schrieb Nico Golde:
> Hi Hanno,
>
> * Hanno Böck <hanno@...eck.de> [2008-07-06 19:04]:
> > http://docs.moodle.org/en/Release_Notes#Moodle_1.8.5
> > * KSES related XSS security vulnerability fixed
>
> This should be CVE-2008-1502:
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1502
is about egroupware.
I found no cve related to moodle 1.8.4.
--
Hanno Böck Blog: http://www.hboeck.de/
GPG: 3DBD3B20 Jabber/Mail: hanno@...eck.de
[ CONTENT OF TYPE application/pgp-signature SKIPPED ]
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Hosted by DataForce ISP -
Powered by Openwall GNU/*/Linux