[VIM] Vendor ACK for LearnCenter XSS (CVE-2006-4540)

Steven M. Christey coley at linus.mitre.org
Tue Oct 24 14:09:11 EDT 2006


Received in CVE email.  No Jericho, he didn't include version information.
I'll follow up and double-check to ensure it's distributable and not just
site-specific.

- Steve


===================================================

Date: Mon, 23 Oct 2006 12:04:43 -0400
From: Andy Wiener
To: cve at mitre.org
Subject: Vulnerability patched

Learn.com has installed a patch to fix the vulnerability that your
website posted. I would appreciate it if you could have someone retest
it, and update the announcement on your site. The link to the
announcement is:

 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4540


Regards,

Andy Wiener

Director of Hosting Operations


More information about the VIM mailing list