Summary
The remote host is missing an update to slash
announced via advisory DSA 1633-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201633-1
Insight
It has been discovered that Slash, the Slashdot Like Automated Storytelling Homepage suffers from two vulnerabilities related to insufficient input sanitation, leading to execution of SQL commands (CVE-2008-2231) and cross-site scripting (CVE-2008-2553).
For the stable distribution (etch), these problems have been fixed in version 2.2.6-8etch1.
In the unstable distribution (sid), the slash package is currently uninstallable and will be removed soon.
We recommend that you upgrade your slash package.
Severity
Classification
-
CVE CVE-2008-2231, CVE-2008-2553 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities