date issue

From: dyl18 Oct 2007 23:13
To: Matt 13 of 14
I know nothing about this stuff, including what it is and isn't safe to say in public without giving too much away, but I'm curious to know more. What damage could someone do with this vulnerability? Big damage?
From: Matt19 Oct 2007 00:09
To: dyl 14 of 14

The one reported by FrSIRT is a cross site scripting flaw which allows injection of Javascript into pages.

 

Symantec haven't got back to me yet regarding their discovery.

EDITED: 19 Oct 2007 00:10 by MATT