oss-sec mailing list archives
Re: Multiple XSS vulnerabilities affecting five WordPress Plugins
From: Henri Salo <henri () nerv fi>
Date: Mon, 21 Nov 2016 22:28:16 +0200
On Mon, Nov 21, 2016 at 04:56:13PM +0000, Scott Gravelle wrote:
Any plans to get CVEs assigned to these vulnerabilities you guys found? Our vulnerability scanner does not have a feature to filter off OVE
Maybe you should start handling OVE and other IDs too. Two reasons: 1) MITRE is not always assigning CVEs for WordPress plugin and theme vulnerabilities for unknown reason. It's not like the CVEs are running out 2) MITRE is not assigning CVEs to all software that has previously received a CVE, silently dropping the software to out-of-scope area. Example case: http://www.openwall.com/lists/oss-security/2016/11/10/6 -- Henri Salo
Current thread:
- Multiple XSS vulnerabilities affecting five WordPress Plugins Summer of Pwnage (Nov 19)
- RE: Multiple XSS vulnerabilities affecting five WordPress Plugins Scott Gravelle (Nov 21)
- Re: Multiple XSS vulnerabilities affecting five WordPress Plugins Henri Salo (Nov 21)
- Re: Multiple XSS vulnerabilities affecting five WordPress Plugins Kurt Seifried (Nov 21)
- Re: Multiple XSS vulnerabilities affecting five WordPress Plugins Henri Salo (Nov 21)
- RE: Multiple XSS vulnerabilities affecting five WordPress Plugins Scott Gravelle (Nov 21)