Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-9701

Опубликовано: 09 авг. 2017
Источник: debian

Описание

Cross-site scripting (XSS) vulnerability in MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 allows remote attackers to inject arbitrary web script or HTML via the url parameter to permalink_page.php.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mantisremovedpackage
mantisno-dsawheezypackage
mantisend-of-lifesqueezepackage

Примечания

  • Fixed by https://github.com/mantisbt/mantisbt/commit/d95f070d (1.2.x)

  • http://article.gmane.org/gmane.comp.security.oss.general/15022

  • https://www.mantisbt.org/bugs/view.php?id=19493

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 8 лет назад

Cross-site scripting (XSS) vulnerability in MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 allows remote attackers to inject arbitrary web script or HTML via the url parameter to permalink_page.php.

CVSS3: 6.5
nvd
больше 8 лет назад

Cross-site scripting (XSS) vulnerability in MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 allows remote attackers to inject arbitrary web script or HTML via the url parameter to permalink_page.php.

CVSS3: 6.5
github
больше 3 лет назад

Cross-site scripting (XSS) vulnerability in MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 allows remote attackers to inject arbitrary web script or HTML via the url parameter to permalink_page.php.