Content-Length: 9844 | pFad | http://lwn.net/Articles/407847/

mantis: multiple cross-site scripting flaws [LWN.net]
|
|
Subscribe / Log in / New account

mantis: multiple cross-site scripting flaws

Package(s):mantis CVE #(s):CVE-2010-2574 CVE-2010-3303
Created:September 30, 2010 Updated:November 9, 2012
Description:

From the Red Hat bugzilla entries [1, 2]:

CVE-2010-2574: Cross-site scripting (XSS) vulnerability in manage_proj_cat_add.php in MantisBT 1.2.2 allows remote authenticated administrators to inject arbitrary web script or HTML via the name parameter in an Add Category action.

CVE-2010-3303: XSS vulnerability when uninstalling maliciously named plugins; Multiple XSS issues with custom field enumeration values; XSS issues when using custom field String values; XSS in print_all_bug_page_word.php when printing project and category names

Alerts:
Gentoo 201211-01 mantisbt 2012-11-08
Fedora FEDORA-2010-15082 mantis 2010-09-22
Fedora FEDORA-2010-15080 mantis 2010-09-22

to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds









ApplySandwichStrip

pFad - (p)hone/(F)rame/(a)nonymizer/(d)eclutterfier!      Saves Data!


--- a PPN by Garber Painting Akron. With Image Size Reduction included!

Fetched URL: http://lwn.net/Articles/407847/

Alternative Proxies:

Alternative Proxy

pFad Proxy

pFad v3 Proxy

pFad v4 Proxy