|
Mantis Multiple Cross-Site Scripting Vulnerabilities
|
|
|
|
|
Secunia Advisory:
|
SA18434
|
|
|
Release Date:
|
2006-01-17
|
|
Last Update:
|
2006-02-28
|
|
|
Critical:
|

Less critical
|
|
Impact:
|
Cross Site Scripting
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Patch
|
|
| Software: | Mantis 1.x
|
| | CVE reference: | CVE-2006-0664 (Secunia mirror) CVE-2006-0665 (Secunia mirror) CVE-2006-0841 (Secunia mirror) CVE-2006-0840 (Secunia mirror)
|
|
|
Want to know the next time vulnerabilities are fixed in this product? - Companies can be alerted via email and SMS! |
|
|
Description: Some vulnerabilities have been reported in Mantis, which can be exploited by malicious people to conduct cross-site scripting attacks.
Input passed to various parameters in view_all_set.php, to the "sort" parameter in manage_user_page.php, to the "view_type" parameter in view_filters_page.php, and to the "title" parameter in proj_doc_delete.php isn't properly sanitised before being returned to users. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.
Note: An SQL injection error in the "sort" parameter of manage_user_page.php, that is reportedly not exploitable, has also been fixed.
Solution: Update to version 1.0.0.
http://sourceforge.net/project/showfi...?group_id=14963&package_id=166159
Provided and/or discovered by: Thomas Waldegger
Changelog: 2006-02-16: Updated "Description" and "Solution" sections.
2006-02-21: Added CVE references.
2006-02-27: Added CVE reference.
2006-02-28: Added CVE reference.
Original Advisory: http://bugs.mantisbt.org/view.php?id=6509
http://bugs.mantisbt.org/view.php?id=6557
http://bugs.mantisbt.org/view.php?id=6563
http://bugs.mantisbt.org/view.php?id=6569
http://morph3us.org/advisories/20060214-mantis-100rc4.txt
|
|
|
|
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|
|
|
|
10 Related Secunia Security Advisories
|
|
|
1. Mantis Multiple Vulnerabilities
|
|
2. Mantis "Most Active" Script Insertion Vulnerability
|
|
3. Mantis "Upload File" Script Insertion Vulnerability
|
|
4. Mantis Custom Field Information Disclosure
|
|
5. Mantis Cross-Site Scripting Vulnerabilities
|
|
6. Mantis ADOdb Insecure Test Scripts Security Issues
|
|
7. Mantis Multiple Vulnerabilities
|
|
8. Mantis "view_filters_page.php" Cross-Site Scripting Vulnerability
|
|
9. Mantis Multiple Vulnerabilities
|
|
10. Mantis Multiple Vulnerabilities
|
|
|
Send Feedback to Secunia
|
|
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.
|
|
|
|