Release Date: 2008-10-24
Critical:
Less critical
Impact: Cross Site Scripting
Where: From remote
Solution Status: Unpatched
Software: ClipShare 4.x
Description:
ShockShadow has reported a vulnerability is ClipShare, which can be exploited by malicious people to conduct cross-site scripting attacks.
Input passed to the "title" parameter in fullscreen.php is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session, in the context of an affected site.
This vulnerability is reported in version 4.0. Other versions may also be affected.
Solution:
Edit the source code to ensure that input is properly sanitised.
Provided and/or discovered by:
ShockShadow
Ubuntu update for moodle
Release Date: 2008-10-24
Critical:
Highly critical
Impact: Security Bypass
System access
Where: From remote
Solution Status: Vendor Patch
OS: Ubuntu Linux 7.10
Ubuntu Linux 8.04
Description:
Ubuntu has issued an update for moodle. This fixes a vulnerability, which can be exploited by malicious people to bypass certain security restrictions.
Solution:
Apply updated packages.
Original Advisory:
USN-658-1:
http://www.ubuntu.com/usn/usn-658-1
Other References:
SA30986:
http://secunia.com/advisories/30986/

Chowhound
Comic Vine
GameFAQs
GameSpot
Giant Bomb
TechRepublic