X-Git-Url: http://git.vanrenterghem.biz/git.ikiwiki.info.git/blobdiff_plain/232c8a6dfce9ec58c7959d7a4eaf8d0d3870429e..080a4cb57947a7991ea5781342af5756ed7213ae:/doc/security.mdwn?ds=inline diff --git a/doc/security.mdwn b/doc/security.mdwn index 53222a3a6..353854656 100644 --- a/doc/security.mdwn +++ b/doc/security.mdwn @@ -466,11 +466,11 @@ with the comments plugin enabled. ([[!cve CVE-2011-0428]]) ## possible javascript insertion via insufficient htmlscrubbing of alternate stylesheets -Tango noticed that 'meta stylesheet` directives allowed anyone +Giuseppe Bilotta noticed that 'meta stylesheet` directives allowed anyone who could upload a malicious stylesheet to a site to add it to a -page as an alternate stylesheet. In order to be exploited, the user -would have to select the alternative stylesheet in their browser. +page as an alternate stylesheet, or replacing the default stylesheet. This hole was discovered on 28 Mar 2011 and fixed the same hour with the release of ikiwiki 3.20110328. An upgrade is recommended for sites that have untrusted committers, or have the attachments plugin enabled. +([[!cve CVE-2011-1401]])