Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <20161111194327.GA26873@tunkki>
Date: Fri, 11 Nov 2016 21:43:27 +0200
From: Henri Salo <henri@...v.fi>
To: oss-security@...ts.openwall.com
Cc: mehmet@...metince.net, mr@...buckingham.com
Subject: CVE request: BigTree CMS SQL injection and reflected cross-site
 scripting vulnerabilities fixed in 4.2.12 / 4.1.16

Please assign CVE identifier for BigTree CMS SQL injection and reflected
cross-site scripting vulnerabilities, thanks.

Fixed in 4.2.12 / 4.1.16
Reported by Mehmet İnce in https://github.com/bigtreecms/BigTree-CMS/pull/256

Fixed in:

https://github.com/bigtreecms/BigTree-CMS/commit/7e4b03f89dcf8dc3b0500347e877ddb7a766f23e
https://github.com/bigtreecms/BigTree-CMS/commit/7260b84371c99e29576e8ee22eda7b36fc5da741
https://github.com/bigtreecms/BigTree-CMS/commit/50bfa22c5861657470803669a0283053d8b67338

-- 
Henri Salo

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.