<html>
  <head>
    <meta content="text/html; charset=windows-1252"
      http-equiv="Content-Type">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    <br>
    -----BEGIN PGP SIGNED MESSAGE-----<br>
    Hash: SHA256<br>
    <br>
    4.12-5<br>
    <br>
    On 03/02/2016 01:57 AM, Brian Pocock wrote:<br>
    <span style="white-space: pre;">&gt; What version of Zend.to are you
      running? There is a known XSS in an earlier version of code.<br>
      &gt;<br>
      &gt; Brian Pocock - Consultant<br>
      &gt; Nebulas <br>
      &gt;<br>
      &gt; On 1 Mar 2016, at 22:14, Keith Erekson &lt;<a class="moz-txt-link-abbreviated" href="mailto:kbe2@lehigh.edu">kbe2@lehigh.edu</a>
      <a class="moz-txt-link-rfc2396E" href="mailto:kbe2@lehigh.edu">&lt;mailto:kbe2@lehigh.edu&gt;</a>&gt; wrote:<br>
      &gt;<br>
      &gt;&gt;<br>
      &gt; Tested on Mac OS X 10.10, seems to work in Firefox (41 and
      44), but not Chrome (48) nor Safari (9).<br>
      &gt;<br>
      &gt; (pickup.php, not pickup/php for anyone who wants to try)<br>
      &gt;<br>
      &gt; ~Keith<br>
      &gt;<br>
      &gt; On 03/01/2016 02:14 PM, Chris Venter wrote:<br>
      &gt; &gt; Hi<br>
      &gt;<br>
      &gt;<br>
      &gt;<br>
      &gt;       &gt; Our security audit has highlighted a possible
      reflected cross<br>
      &gt;       site scripting error on the pickup.php page,to test we
      ran<br>
      &gt;<br>
      &gt;<br>
      &gt;<br>
      &gt;       &gt; <a class="moz-txt-link-freetext" href="https://server_name/pickup/php?emailAddr=test">https://server_name/pickup/php?emailAddr=test</a>"<br>
      &gt;       /&gt;&lt;script&gt;alert('XSS Test')&lt;/script&gt;<br>
      &gt;<br>
      &gt;<br>
      &gt;<br>
      &gt;       &gt; Can anyone else confirm if this is an issue?<br>
      &gt;<br>
      &gt;<br>
      &gt;<br>
      &gt;       &gt; Thanks<br>
      &gt;<br>
      &gt;       &gt; CJ<br>
      &gt;<br>
      &gt;<br>
      &gt;<br>
      &gt;<br>
      &gt;<br>
      &gt;       &gt; _______________________________________________<br>
      &gt;<br>
      &gt;       &gt; ZendTo mailing list<br>
      &gt;<br>
      &gt;       &gt; <a class="moz-txt-link-abbreviated" href="mailto:ZendTo@zend.to">ZendTo@zend.to</a><br>
      &gt;<br>
      &gt;       &gt;
      <a class="moz-txt-link-freetext" href="http://mailman.ecs.soton.ac.uk/mailman/listinfo/zendto">http://mailman.ecs.soton.ac.uk/mailman/listinfo/zendto</a><br>
      &gt;<br>
      &gt;&gt;<br>
      &gt;&gt; _______________________________________________<br>
      &gt;&gt; ZendTo mailing list<br>
      &gt;&gt; <a class="moz-txt-link-abbreviated" href="mailto:ZendTo@zend.to">ZendTo@zend.to</a> <a class="moz-txt-link-rfc2396E" href="mailto:ZendTo@zend.to">&lt;mailto:ZendTo@zend.to&gt;</a><br>
      &gt;&gt; <a class="moz-txt-link-freetext" href="http://mailman.ecs.soton.ac.uk/mailman/listinfo/zendto">http://mailman.ecs.soton.ac.uk/mailman/listinfo/zendto</a><br>
      &gt; *Company name:* Nebulas Solutions Group Ltd *Company
      Registration Number:* 04281153 *Place of Registration:* England
      and Wales *Registered Office Address:* 256 Waterloo Road, London,
      SE1 8RF<br>
      &gt;<br>
      &gt;<br>
      &gt; _______________________________________________<br>
      &gt; ZendTo mailing list<br>
      &gt; <a class="moz-txt-link-abbreviated" href="mailto:ZendTo@zend.to">ZendTo@zend.to</a><br>
      &gt; <a class="moz-txt-link-freetext" href="http://mailman.ecs.soton.ac.uk/mailman/listinfo/zendto">http://mailman.ecs.soton.ac.uk/mailman/listinfo/zendto</a></span><br>
    <br>
    -----BEGIN PGP SIGNATURE-----<br>
    Version: GnuPG v1.4.12 (GNU/Linux)<br>
    <br>
    iQEcBAEBCAAGBQJW1y3fAAoJEMdFVhhDm2SFEhIH/2P6RW7MOzcQuAeXvfZ0Nhi7<br>
    ibG4eWItPWFizpWVec8E4rJZI9BX/3dHmwKzwf5VKHSHASywr0q4kchBYaalseeH<br>
    OcFEjKf3AlPH1rPW9l3bRxCjVKl7C5dP3s8rJpWYHCAr3uhJnv9ddC0pGUfeXafG<br>
    ccbsIU3aJ7SbLM9E6zWX9rBXAFcSpgXjydEVyqGiZ1Atl5jpeyl38EsKZmi+81uZ<br>
    ddEey+LPyHeXjbCxa/BgwCW/2WOC7vy7G9wComED4O8uw+VExhG0jMxv8sqcGdzS<br>
    cT0pqClcXWTgcj293WFi/Ek6gxiHCHcR/N/TNF8w9eLLUcz2wJJkekU3CKiD0a0=<br>
    =1x2p<br>
    -----END PGP SIGNATURE-----<br>
    <br>
  </body>
</html>