So You Just Received A Vulnerability Report. Now What?
charleshooper.net
charleshooper.net
where many vulnerabilities are released to the public. This is in case the reporter goes public without you knowing it.
Also it's a good idea to look the list over and see what types of vulnerabilities are hitting applications. Don't just fix a single reported exploit and call it a day. Find out what else could be wrong security wise with your code and fix those issues as well.