[Secure-testing-commits] r25012 - data/CVE

Henri Salo fgeek-guest at moszumanska.debian.org
Thu Jan 2 08:11:39 UTC 2014


Author: fgeek-guest
Date: 2014-01-02 08:11:39 +0000 (Thu, 02 Jan 2014)
New Revision: 25012

Modified:
   data/CVE/list
Log:
CVE-2013-7233 NOTE

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2014-01-02 08:06:00 UTC (rev 25011)
+++ data/CVE/list	2014-01-02 08:11:39 UTC (rev 25012)
@@ -42,6 +42,7 @@
 	RESERVED
 CVE-2013-7233 (Cross-site request forgery (CSRF) vulnerability in the retrospam ...)
 	- wordpress <unfixed> (unimportant)
+	NOTE: issue only allows comments from posts to be moved to "needs moderation" list
 CVE-2013-7232 (SQL injection vulnerability in ESRI ArcGIS for Server through 10.2 ...)
 	NOT-FOR-US: ESRI ArcGIS
 CVE-2013-7231 (Cross-site scripting (XSS) vulnerability in the Mobile Content Server ...)




More information about the Secure-testing-commits mailing list