summaryrefslogtreecommitdiffstats
path: root/packaging
diff options
context:
space:
mode:
authorKai Blin <kai@samba.org>2011-07-07 10:03:33 +0200
committerKarolin Seeger <kseeger@samba.org>2011-07-24 20:39:25 +0200
commitd401ccaedaec09ad6900ec24ecaf205bed3e3ac1 (patch)
tree8152422cff9e3461e0c7684a654a2e2f8a27710b /packaging
parent5d2d4fbf5bcf6aa1c1d994adaed22dec3ba09b9c (diff)
downloadsamba-d401ccaedaec09ad6900ec24ecaf205bed3e3ac1.tar.gz
samba-d401ccaedaec09ad6900ec24ecaf205bed3e3ac1.tar.xz
samba-d401ccaedaec09ad6900ec24ecaf205bed3e3ac1.zip
s3 swat: Fix possible XSS attack (bug #8289)
Nobuhiro Tsuji of NTT DATA SECURITY CORPORATION reported a possible XSS attack against SWAT, the Samba Web Administration Tool. The attack uses reflection to insert arbitrary content into the "change password" page. This patch fixes the reflection issue by not printing user-specified content on the website anymore. Signed-off-by: Kai Blin <kai@samba.org> CVE-2011-2694.
Diffstat (limited to 'packaging')
0 files changed, 0 insertions, 0 deletions