A little while ago there was this disclosure about a potential Local File Inclusion bug in Drupal core. The issue report was lacking in two areas:
- It did not have enough information about how to take advantage of the vulnerability - this is a classic problem with security reports is that they are not complete enough.
- It was sent to a public list before being sent to the Drupal security team which could have resulted in a zero-day exploit.
Recent comments
3 min 15 sec ago
2 weeks 3 days ago
4 weeks 5 days ago
5 weeks 4 days ago
11 weeks 4 days ago