View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 0006914 | mantisbt | security | public | 2006-04-04 17:41 | 2006-10-09 11:55 |
| Reporter | pchaintreuil | Assigned To | thraxisp | ||
| Priority | normal | Severity | major | Reproducibility | always |
| Status | closed | Resolution | duplicate | ||
| Product Version | 1.0.1 | ||||
| Summary | 0006914: 1.0.1 XSS vuln. (view_all_set.php: start_day, start_year, start_month) | ||||
| Description | A friend just forwarded this URL to me: Quote:############################################### Vuln. Description: Mantis contains a flaw that allows a remote cross site scripting attack. This examples: /view_all_set.php?type=1&temporary=y&do_filter_by_date /view_all_set.php?type=1&temporary=y&do_filter_by_date= /view_all_set.php?type=1&temporary=y&do_filter_by_date ############################################### | ||||
| Tags | No tags attached. | ||||