Hello,
we noticed the following entries in the changelog for SPINE 1.2 stable
and are about to release an advisory for these issues.
* Added in Admin : Forced POST access (prevent XSS)
* Fixed in Core : Placeholders in database handler : security fix
* Fixed in Admin : Macro admin security bug fix
Before we publish our advisory we would appreciate to receive your
comments on these issues.
What are the impacts of the fixed vulnerabilities?
How can they be exploited and is any authentication required?
Which other versions are also affected and are there any mitigating
factors?
Please respond as soon as possible.
Thanks in advance and kind regards,
Huh? (Score:2)
That's interesting. The "macro admin security fix" is something I don't understand, but the first two should be no brainers. Why the heck can't they figure that out for themselves? I do understand your reluctance to get specific about "here's how you attack unpatched versions of this software."
Re: (Score:1)
http://site.com/admin/delete?name=page.. but then again, they can still do a form with POST and have a javascript link to submit it.. *ARGH*The second one is just applying some best practices. Adding an extra lock to the already locked door.
Third one is uhm.. mmm will have to look up what I meant by that tho
Recommended action would be to upgrade.. obviously but not
Not that far-fetched (Score:1)
I don’t see what’s so unusual about the request. Figuring out the issues requires study of the source code, and evaluating them to figure out what follows from them is often unclear to someone without a good understanding of the codebase. This has been a point of tension between the Linux kernelhackers and distributors, who often can’t tell how significant a bugfix really is without either being told or investing significant effort of their own.
Let’s take a look at the questions:
Re: (Score:2)
Fair enough. I stand correct :)
Re: (Score:2)
Er, corrected!
Re: (Score:1)
Don’t worry, after all these times I wrote “privile d ge” in that comment, your transgression is quite minor. Ugh. *hides in shame*