Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Tue, 31 Jul 2012 12:22:16 +1200
From: Robbie MacKay <>
Cc: Heather Leson <>
Subject: CVE request for Ushahidi

The Ushahidi team have been notified of the following security
vulnerabilities thanks to volunteers from OWASP Portland.
These will be fixed in the upcoming 2.5 release.
Could you please allocate CVEs for the following issues?

* Multiple SQL injections (Reported by Timothy D. Morgan, Kees Cook,
postmodern )

* Missing authentication on comments, reports, email API calls
(Reported by Kees
Cook, Dennison Williams)

* User details exposed in comments API (Discovered by internal dev team)

* Admin user hijacking through the installer (Reported by Wil Clouser)

* Stored XSS on member profile pages (Reported by Amy K. Farrell)

Thanks in advance,

Robbie Mackay

Software Developer, External Projects
Ushahidi Inc
skype: robbie.mackay

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.