Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Mon, 5 Jan 2015 09:56:24 -0800
From: Korvin Szanto <>
To: Henri Salo <>
Cc:,,,, Simo Ben youssef <>
Subject: Re: CVE request: Concrete5 XSS vulnerability

This has been fixed in 5.7.3 for some time

We have a security disclosure program for this so any disclosure
outside of our program is very irresponsible and unprofessional. You
end up with outdated information and leave us unable to fix the issue
in a secure way since we cannot see it until it's brought to our
attention through our disclosure program.

On Fri, Jan 2, 2015 at 11:43 AM, Henri Salo <> wrote:
> Hash: SHA1
> Can you assign CVE identifier for following vulnerability in Concrete5, thanks.
> ps. there is something wrong with it
> says "an error occurred while processing this directive"
> - --
> Henri Salo
> Version: GnuPG v1.4.12 (GNU/Linux)
> iEYEARECAAYFAlSm9P4ACgkQXf6hBi6kbk+bfQCgjF/EWeO4Wfs0SUSsq96LwNpE
> AWAAn1yKEw9eDAlJ6cQczjzHZ7VGdXUp
> =0mVH

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.