cross site scripting bug in dnslook.html

jwiens

Member
Mar 8, 2004
16
0
151
Just an fyi so folks know they should update. Not a super huge vulnerability but still potentially a problem (for a long and detailed summary of what XSS is and why it matters, see my old post on the subject).

http://www.securityfocus.com/bid/21142

Security focus says no solution is out, however Secunia claims that you can update to version 10.9.0 R75 to be secure. I imagine they've got it right and since it looks like a fix is available I figure folks should be aware so they can patch.
 

pjman

Well-Known Member
Mar 22, 2003
101
0
166
New York
Secunia is always on top of it.

I don't even bother looking at anything Security focus puts out. Secunia is a much better source.