View Issue Details

IDProjectCategoryView StatusLast Update
0015234MantisTouchGeneralpublic2013-05-17 03:18
Reportertrehn Assigned Tovboctor  
PrioritynormalSeverityminorReproducibilityalways
Status closedResolutionfixed 
Product Version1.2.1 
Fixed in Version1.2.2 
Summary0015234: Exception messages are not escaped in http_header_redirect()
Description

In the code of Mantis Touch there are some calls of http_header_redirect() where an exception message is passed directly as a GET parameter of the target url. If this message contains a line feed "\n", PHP stops with a warning in core/http_api.php +11.

TagsNo tags attached.

Activities

There are no notes attached to this issue.