zomg

Someone wastes Heine's time - He gives them proper credit

in

A little while ago there was this disclosure about a potential Local File Inclusion bug in Drupal core. The issue report was lacking in two areas:

  1. It did not have enough information about how to take advantage of the vulnerability - this is a classic problem with security reports is that they are not complete enough.
  2. It was sent to a public list before being sent to the Drupal security team which could have resulted in a zero-day exploit.
Syndicate content