Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Web applications security vulnerabilities (PHP, ASP, CGI, Perl, etc)

  [SA18016] EveryAuction "searchstring"
Cross-Site Scripting Vulnerability

  mcGallery PRO vuln.

  IMOEL CMS Sql password discovery

  Guestserver guestbook system vulnerabilities

From:r0t <krustevs_(at)_googlemail.com>
Date:13.12.2005
Subject:Mantis bugtracking system XSS vuln.

Mantis bugtracking system XSS vuln.

Vuln. dicovered by : r0t
Date: 13 dec. 2005
orginal advisory:
http://pridels.blogspot.com/2005/12/mantis-bugtracking-system-xss-vuln.html

vendor:http://www.mantisbt.org/
affected version: 1.0.0rc3,1.0.0rc2 and prior




Product Description:

Mantis is a web-based bugtracking system. It is written in the PHP scripting language and requires the MySQL database and a webserver. Mantis has been installed on Windows, Mac OS, OS/2, and a variety of Unix operating systems. Almost any web browser should be able to function as a client. It is released under the terms of the GNU General Public License (GPL).
Mantis is free to use and modify. It is free to redistribute as long as you abide by the distribution terms of the GPL.



Vuln. Description:

Mantis contains a flaw that allows a remote cross site scripting attack. This flaw exists because input passed to  "target_field" parameter in "view_filters_page.php" isn't properly sanitised before being returned to the user.
This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.



example:
/view_filters_page.php?for_screen=1&target
_field=%22%3E%3Cscript%3Ealert('r0t')%3C/
script%3E


Solution:
Edit the source code to ensure that input is properly sanitised.

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru