Release date:
Updated on:
Affected Systems:
StatusNet 0.9.8
StatusNet 0.8
Unaffected system:
StatusNet 0.9.9
Description:
--------------------------------------------------------------------------------
Bugtraq id: 49113
StatusNet, formerly Laconica, is an open-source microblog platform software developed using PHP.
StatusNet has a cross-site scripting vulnerability in the implementation of tag stream pages. Remote attackers can exploit this vulnerability to execute arbitrary script code in the user browsers of the affected sites to steal Cookie authentication creden.
This vulnerability occurs because some input transmitted through URL related to the "tag stream" page is not properly filtered before being returned to the user.
<* Source: Yvan Boily
Link: http://status.net/2011/08/02/security-alert-for-all-versions-of-statusnet
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
StatusNet
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://status.net/