In association with heise online

19 February 2007, 13:29

Security update for OS Tube

The developers of video portal application OS Tube (the link is to the German home site; their English language pages are not yet ready), released just last week, have now released a security update. In the announcement regarding the update, the developers speak generally of bug fixes for variable passing. This relates, however, to variables which can be entered by the user, and which are passed on by the scripts without checking or filtering.

This made OS Tube vulnerable to SQL command injection and cross-site scripting. The vulnerabilities affect both the free Community and the commercial Pro versions of OS Tube. The developers recommend installing the update sharpish.

See also:

(ehe)

  • Share this article
  • Twitter
  • Facebook
  • digg this
  • submit to slashdot
  • post to delicious
  • StumbleUpon
  • submit to reddit







The H open source

The H Security

The H Internet Toolkit