MantisBT Cross Site Scripting and SQL Injection Vulnerabilities
BID:49235
Info
MantisBT Cross Site Scripting and SQL Injection Vulnerabilities
| Bugtraq ID: | 49235 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-2938 CVE-2011-2938 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 18 2011 12:00AM |
| Updated: | Apr 13 2015 09:39PM |
| Credit: | Net.Edit0r |
| Vulnerable: |
Mantisbt Mantisbt 1.1.8 Mantisbt Mantisbt 1.1.7 Mantisbt Mantisbt 1.1.5 Mantisbt Mantisbt 1.1 Mantisbt Mantisbt 1.0.8 Mantisbt Mantisbt 1.0.7 Mantisbt Mantisbt 1.0.6 Mantisbt Mantisbt 1.0.2 Mantisbt Mantisbt 0.19.4 Mantisbt Mantisbt 0.19.3 Mantisbt Mantisbt 1.2.2 Mantisbt Mantisbt 1.2.1 Mantisbt Mantisbt 1.1.6 Mantisbt Mantisbt 1.1.4 Mantisbt Mantisbt 1.1.2 Mantisbt Mantisbt 1.1.1 Mantisbt Mantisbt 1.1.0 Mantisbt Mantisbt 1.0.5 Mantisbt Mantisbt 1.0.4 Mantisbt Mantisbt 1.0.3 Mantisbt Mantisbt 1.0.2 Mantisbt Mantisbt 1.0.1 jackdewey Link Library 5.0.8 Gentoo Linux |
| Not Vulnerable: | |
Discussion
MantisBT Cross Site Scripting and SQL Injection Vulnerabilities
MantisBT is prone to an SQL-injection vulnerability and a cross-site scripting vulnerability.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
MantisBT 1.2.6 is vulnerable; other versions may also be affected.
MantisBT is prone to an SQL-injection vulnerability and a cross-site scripting vulnerability.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
MantisBT 1.2.6 is vulnerable; other versions may also be affected.
Exploit / POC
MantisBT Cross Site Scripting and SQL Injection Vulnerabilities
An attacker can use a browser to exploit these issues. To exploit cross-site scripting issues, the attacker must entice an unsuspecting victim to follow a malicious URI.
The following proof of concept URIs are available:
http://www.example.com/path/search.php?project_id=[XSS]
http://www.example.com/path/core.php?mbadmin=[SQL]
An attacker can use a browser to exploit these issues. To exploit cross-site scripting issues, the attacker must entice an unsuspecting victim to follow a malicious URI.
The following proof of concept URIs are available:
http://www.example.com/path/search.php?project_id=[XSS]
http://www.example.com/path/core.php?mbadmin=[SQL]
Solution / Fix
MantisBT Cross Site Scripting and SQL Injection Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
MantisBT Cross Site Scripting and SQL Injection Vulnerabilities
References:
References:
- MantisBT CMS SQL Injection / Cross Site Scripting (MantisBT)
- Vendor Homepage (MantisBT)