View Issue Details

IDProjectCategoryView StatusLast Update
0005750mantisbtsecuritypublic2005-07-23 02:28
Reporterspud Assigned Tovboctor  
PrioritynormalSeverityminorReproducibilityalways
Status closedResolutionduplicate 
Summary0005750: Javascript XSS vulnerability
Description

I had a user create an "issue" that contained only this:

<script>alert("your bug tracking is vulnearble to xss");</script>

For the most part, the hack is rendered ineffective, which is nice. However, upon attempting to delete this bogus entry, I clicked the "Delete Issue" button, which started to load bug_actiongroup_page.php. Just before the page finished loading, what happened? I got a javascript alert that said "your bug tracking is vulnearble to xss"! So indeed it is...at least if you try to delete it!

I left it up, so you can see the bogus entry as-is: http://bugs.dadaimc.org/view.php?id=160

Additional Information

PS: Sorry for the dupe of the custom field bug earlier! I didn't look hard enough for it before submitting. The CVS patch works great!

TagsNo tags attached.

Relationships

duplicate of 0005751 closedthraxisp Javascript XSS vulnerability 

Activities

spud

spud

2005-06-08 18:38

reporter   ~0010442

Ack! My net connection kept dropping, so I never got to the "Submitted" page, and figured it wasn't! Huge apologies, I know how annoying this is...