In association with heise online

19 February 2007, 12:29

Security update for OS Tube

  • Twitter
  • Facebook
  • submit to slashdot
  • StumbleUpon
  • submit to reddit

The developers of video portal application OS Tube (the link is to the German home site; their English language pages are not yet ready), released just last week, have now released a security update. In the announcement regarding the update, the developers speak generally of bug fixes for variable passing. This relates, however, to variables which can be entered by the user, and which are passed on by the scripts without checking or filtering.

This made OS Tube vulnerable to SQL command injection and cross-site scripting. The vulnerabilities affect both the free Community and the commercial Pro versions of OS Tube. The developers recommend installing the update sharpish.

See also:

(ehe)

Print Version | Send by email | Permalink: http://h-online.com/-732319
 


  • July's Community Calendar





The H Open

The H Security

The H Developer

The H Internet Toolkit