Security update for OS Tube
The developers of video portal application OS Tube (the link is to the German home site; their English language pages are not yet ready), released just last week, have now released a security update. In the announcement regarding the update, the developers speak generally of bug fixes for variable passing. This relates, however, to variables which can be entered by the user, and which are passed on by the scripts without checking or filtering.
This made OS Tube vulnerable to SQL command injection and cross-site scripting. The vulnerabilities affect both the free Community and the commercial Pro versions of OS Tube. The developers recommend installing the update sharpish.
- Announcement and download for the OS Tube update