@attritionorg Is it possible for an individual to request a CVE number for a Webapp vulnerability.
@csVSN Yes. http://bit.ly/VISkkI The doc there has the email address to use.
-
-
@attritionorg Yeah, I did emailed(cve-assign@****.org) them some 20 hours ago still no reply. Should i send a POC to that particular email? -
@csVSN No, should be patient =) Same with vendor contact. Not everyone responds immediately. CVE is swamped probably. -
@attritionorg :D Ok i will be patient for CVE but for vendor how long can i wait? 48 hours? -
@csVSN Ultimately your call, but many people give 5 - 10 business days for an initial reply. Read that article re: disclosure policies. - 1 more reply
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.