View Issue Details

IDProjectCategoryView StatusLast Update
0006562mantisbtsecuritypublic2006-10-09 11:55
Reporterthraxisp Assigned Tothraxisp  
PrioritynormalSeverityminorReproducibilityalways
Status closedResolutionno change required 
Product Version0.19.3 
Summary0006562: XSS Vulnerability in project documents (TKADV2005-11-002)
Description

It is possible to embed an XSS script into the information passed to proj_doc_delete. It is primarily cosmetic.

From Thomas Waldegger [thomas.waldegger at morph3us dot org]

/proj_doc_delete.php:

<?file_id=1&title=%22%3E%3Cscript%3Ealert(document.cookie)%3C/
script%3E>

TagsNo tags attached.

Relationships

parent of 0006563 closedthraxisp Port XSS Vulnerability in project documents (TKADV2005-11-002) 
parent of 0006564 closedthraxisp Port XSS Vulnerability in project documents (TKADV2005-11-002) 

Activities

thraxisp

thraxisp

2006-01-05 21:35

reporter   ~0011876

This issue doesn't affect 0.19.3.