Mantis 'summary_api.php' HTML Injection Vulnerability
BID:43837
Info
Mantis 'summary_api.php' HTML Injection Vulnerability
| Bugtraq ID: | 43837 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-3763 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 14 2010 12:00AM |
| Updated: | Apr 13 2015 10:21PM |
| Credit: | atrol |
| Vulnerable: |
Mantis Mantis 1.2.2 Mantis Mantis 1.2.1 Mantis Mantis 1.1.4 Mantis Mantis 1.1.3 Mantis Mantis 1.1.2 Mantis Mantis 1.1.1 Mantis Mantis 1.1 Mantis Mantis 1.0.1 Mantis Mantis 1.0 .0RC4 Mantis Mantis 1.0 .0RC3 Mantis Mantis 1.0 .0rc2 Mantis Mantis 1.0 .0rc1 Mantis Mantis 1.0 .0a3 Mantis Mantis 1.0 .0a2 Mantis Mantis 1.0 .0a1 Mantis Mantis 1.0 Mantis Mantis 1.1.0a2 Mantis Mantis 1.0.0 RC5 Gentoo Linux |
| Not Vulnerable: |
Mantis Mantis 1.2.3 |
Discussion
Mantis 'summary_api.php' HTML Injection Vulnerability
Mantis is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Versions prior to Mantis 1.2.3 are vulnerable.
Mantis is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Versions prior to Mantis 1.2.3 are vulnerable.
Exploit / POC
Mantis 'summary_api.php' HTML Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Mantis 'summary_api.php' HTML Injection Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Mantis 'summary_api.php' HTML Injection Vulnerability
References:
References:
- Mantis Homepage (Mantis)
- mantisbt - Change Log (Mantis)