Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Sat, 7 Jul 2012 00:21:40 +0200
From: Marcus Meissner <>
To: OSS Security List <>
Subject: CVE Request: XSS in a Mono System.web error page 


A Nessus scan of a Novell product using Mono Web revealed a XSS attack
in the Mono System.Web library.

The Mono team commited a fix to their GIT.


The XSS is in the error popup of the "Forbidden extension" filter method,
which filters out e.g. ".dll" files.

Ciao, Marcus

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.