TE
TechEcho
Home
24h Top
Newest
Best
Ask
Show
Jobs
English
GitHub
Twitter
Home
Only two remote holes in the default install, in more than 10 years
17 points
by
gopher
almost 17 years ago
6 comments
there
almost 17 years ago
oh no, a lame xss bug in a 3rd party cgi script that runs on a solaris web server hosting a website that uses no cookies. surely this is big news!
shadytrees
almost 17 years ago
You have achieved the difficult task of making CVS less usable.
dguido
almost 17 years ago
This was posted on full-disclosure August 6th.<p><a href="http://seclists.org/fulldisclosure/2008/Aug/0074.html" rel="nofollow">http://seclists.org/fulldisclosure/2008/Aug/0074.html</a>
gstar
almost 17 years ago
Collapse
I cant decide if that's classy or cheeky.<p>But regardless, I dont know if a bug in cvsweb counts as openbsd - does it?
评论 #282859 未加载
stassats
almost 17 years ago
Collapse
Is that a hole? Is that a default install?
评论 #282739 未加载
tptacek
almost 17 years ago
OH NOEZ! U G0TZ MY CVSWEB COOKEEZ!