[dokuwiki] Re: About XSS and bug #1195

  • From: Andreas Gohr <andi@xxxxxxxxxxxxxx>
  • To: dokuwiki@xxxxxxxxxxxxx
  • Date: Tue, 24 Jul 2007 21:15:44 +0200

On Tue, 24 Jul 2007 14:34:12 -0400
"Oliver Schulze L." <oliver@xxxxxxxxxxxxx> wrote:

> Hi,
> I noted yesterday the notice on my wiki about a XSS bug.
> 
> Is this a serious/common/exploitable bug? Is the upgrade considered
> crucial?

I don't consider it crucial, but it could be used to steal user
cookies. So I recommend to fix the bug manually at least.

Andi

-- 
http://www.splitbrain.org

Other related posts: