MantisBT <1.2.7 search.php multiple XSS vulnerabilities
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Gentoo Linux |
Fix Released
|
Low
|
|||
mantis (Debian) |
Fix Released
|
Unknown
|
|||
mantis (Fedora) |
Fix Released
|
Medium
|
|||
mantis (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned |
Bug Description
Original vulnerability report by Net.Edit0r (<email address hidden>) from BlACK Hat Group [http://
MantisBT bug report for full details of the issue: http://
Please note that the second SQL injection vulnerability identified by Net.Edit0r is not reproducible (refer to the MantisBT bug report above for reasons why).
A patch for 1.2.6 is available at:
https:/
MantisBT 1.2.7 is currently being packaged and will be available shortly through usual channels.
A CVE request and notice has been sent to <email address hidden>
CVE References
visibility: | private → public |
Changed in gentoo: | |
importance: | Unknown → Critical |
status: | Unknown → New |
Changed in mantis (Debian): | |
status: | Unknown → Confirmed |
Changed in mantis (Debian): | |
status: | Confirmed → Fix Released |
Changed in gentoo: | |
importance: | Critical → Low |
Changed in gentoo: | |
status: | New → Fix Released |
Changed in mantis (Fedora): | |
importance: | Unknown → Medium |
status: | Unknown → Fix Released |
Original vulnerability report by Net.Edit0r (<email address hidden>) from BlACK Hat Group [http:// black-hg. org] is available at: packetstormsecu rity.org/ files/104149
http://
MantisBT bug report for full details of the issue: http:// www.mantisbt. org/bugs/ view.php? id=13245
Please note that the second SQL injection vulnerability identified by Net.Edit0r is not reproducible (refer to the MantisBT bug report above for reasons why).
A patch for 1.2.6 is available at: /github. com/mantisbt/ mantisbt/ commit/ 317f3db3a3c6877 5de3acf3b15f55b 1e3c18f93b
https:/
MantisBT 1.2.7 is currently being packaged and will be available shortly through usual channels for distributions and standalone users to pick up.
Reproducible: Always