Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Sun, 24 Jul 2011 18:23:27 +0300
From: Henri Salo <henri@...v.fi>
To: oss-security@...ts.openwall.com
Cc: justin@...irish.net
Subject: CVE request: Drupal Data-module multiple vulnerabilities

These issues does not have CVE-identifiers. Could we get one?

http://seclists.org/fulldisclosure/2011/Feb/219

I asked from Justin Klein Keane and he wasn't aware of CVE-identifier. I think this needs identifier even this is an alpha release as this module is used by some production instances. If I am correct two identifiers should be enough. One for XSS and another for SQL injections.

Discussion about the issue: http://drupal.org/node/1056470

Best regards,
Henri Salo

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.