[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-3017-1 -- php-cas

ID: oval:org.secpod.oval:def:21032Date: (C)2014-09-09   (M)2023-11-13
Class: PATCHFamily: unix




Marvin S. Addison discovered that Jasig phpCAS, a PHP library for the CAS authentication protocol, did not encode tickets before adding them to an URL, creating a possibility for cross site scripting.

Platform:
Debian 7.0
Product:
php-cas
Reference:
DSA-3017-1
CVE-2014-4172
CVE    1
CVE-2014-4172
CPE    2
cpe:/o:debian:debian_linux:7.x
cpe:/a:jasig:php-cas

© SecPod Technologies