Versions Affected: v.2007-2 (Other versions may also be affected)
Severity: XSS
Input passed to "wiki" in "index.php" is not properly sanitised before
being used. This can be exploited to insert arbitrary HTML and script code,
which is executed in a user's browser session in context of an affected
site when malicious data is viewed.
1. Contacted the author at April 09, 2008 via sourceforge tracker (no
response).
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Maksymilian Arciemowicz discovered a Integer Overflow
vulnerability in the libc library "strfmon()" function.A vulnerability could allow an attacker who successfully exploits this vulnerability to take control of the affected *BSD systems.