Currently the posts are filtered by: Security
Reset this filter to see all posts.
A vulnerability has been discovered in the todoyu third party library calendar, which can be exploited by malicious people to conduct cross-site scripting attacks (read the report).
Input passed via the "lang" parameter to lib/js/jscalendar/php/test.php is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.
Although the criticality level is classified as low, please update your todoyu installation to version 2.0.9.
10.05.2012 15:33
todoyu 2.2 发布,PHP项目/任务管理todoyu是一个PHP开源的任务/项目管理,时间跟踪和协作开发应用程序。它拥有一个流行的Ajax操作界面,在每个项目上都可以有用户和客http://t.co/bGnGfbFI http://t.co/VA53raBB
10.05.2012 14:35
todoyu 2.2.0 http://t.co/6JFGKyIU
follow us on
www.twitter.com/todoyu