CVE-2005-3090

Cross-site scripting (XSS) vulnerability in bug_actiongroup_page.php in Mantis 0.19.0a1 through 1.0.0a3 allows remote attackers to inject arbitrary web script or HTML via the summary of the bug, which is not quoted when view_all_bug_page.php is used to delete the bug, as identified by bug#0006002, a different vulnerability than CVE-2005-2557.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mantis:mantis:0.19.0:*:*:*:*:*:*:*
cpe:2.3:a:mantis:mantis:0.19.0_rc1:*:*:*:*:*:*:*
cpe:2.3:a:mantis:mantis:0.19.0a1:*:*:*:*:*:*:*
cpe:2.3:a:mantis:mantis:0.19.0a2:*:*:*:*:*:*:*
cpe:2.3:a:mantis:mantis:0.19.1:*:*:*:*:*:*:*
cpe:2.3:a:mantis:mantis:0.19.2:*:*:*:*:*:*:*
cpe:2.3:a:mantis:mantis:1.0.0a1:*:*:*:*:*:*:*
cpe:2.3:a:mantis:mantis:1.0.0a2:*:*:*:*:*:*:*
cpe:2.3:a:mantis:mantis:1.0.0a3:*:*:*:*:*:*:*

History

21 Nov 2024, 00:01

Type Values Removed Values Added
References () http://marc.info/?l=bugtraq&m=112786017426276&w=2 - () http://marc.info/?l=bugtraq&m=112786017426276&w=2 -
References () http://www.debian.org/security/2005/dsa-778 - Patch, Vendor Advisory () http://www.debian.org/security/2005/dsa-778 - Patch, Vendor Advisory

Information

Published : 2005-09-28 22:03

Updated : 2024-11-21 00:01


NVD link : CVE-2005-3090

Mitre link : CVE-2005-3090

CVE.ORG link : CVE-2005-3090


JSON object : View

Products Affected

mantis

  • mantis