View Issue Details

IDProjectCategoryView StatusLast Update
0006510mantisbtsecuritypublic2006-10-09 11:55
Reporterthraxisp Assigned Tothraxisp  
PrioritynormalSeverityminorReproducibilityalways
Status closedResolutionfixed 
Product Versiongit trunk 
Fixed in Version1.1.0a1 
Summary0006510: Port: Additional XSS Vulnerabilities in Filter
Description

Some XSS vulnerabilities in the filter were missed in the last patch.

GET: ?type=1&highlight_changed=[XSS]
GET: ?type=1&relationship_type=[XSS]
GET: ?type=1&relationship_bug=[XSS]

Originally reported by Thomas Waldegger thomas.waldegger@morph3us.org

TagsNo tags attached.

Relationships

child of 0006508 closedthraxisp Additional XSS Vulnerabilities in Filter 
child of 0005460 closedvboctor Critical Issues to Fix for Mantis 1.0.0 Release 

Activities

thraxisp

thraxisp

2005-12-18 09:29

reporter   ~0011814

Fixed in CVS.

view_all_set.php -> 1.60
core/filter_api.php -> 1.131