MantisBT Multiple Local File Include and Cross Site Scripting Vulnerabilities
BID:49448
Info
MantisBT Multiple Local File Include and Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 49448 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-3356 CVE-2011-3357 CVE-2011-3358 CVE-2011-3356 CVE-2011-3357 CVE-2011-3358 CVE-2011-3578 CVE-2011-3578 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 05 2011 12:00AM |
| Updated: | Apr 13 2015 08:59PM |
| Credit: | Paulino Calderon, Websec and High-Tech Bridge Security Research Lab |
| Vulnerable: |
Mantisbt Mantisbt 1.2.7 Mantisbt Mantisbt 1.2.6 Mantisbt Mantisbt 1.2.4 Mantisbt Mantisbt 1.2.3 Mantisbt Mantisbt 1.1.8 Mantisbt Mantisbt 1.1.7 Mantisbt Mantisbt 1.1.5 Mantisbt Mantisbt 1.1 Mantisbt Mantisbt 1.0.8 Mantisbt Mantisbt 1.0.7 Mantisbt Mantisbt 1.0.6 Mantisbt Mantisbt 1.0.2 Mantisbt Mantisbt 0.19.4 Mantisbt Mantisbt 0.19.3 Mantisbt Mantisbt 1.2.2 Mantisbt Mantisbt 1.2.1 Mantisbt Mantisbt 1.1.6 Mantisbt Mantisbt 1.1.4 Mantisbt Mantisbt 1.1.2 Mantisbt Mantisbt 1.1.1 Mantisbt Mantisbt 1.1.0 Mantisbt Mantisbt 1.0.5 Mantisbt Mantisbt 1.0.4 Mantisbt Mantisbt 1.0.3 Mantisbt Mantisbt 1.0.2 Mantisbt Mantisbt 1.0.1 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 |
| Not Vulnerable: |
Mantisbt Mantisbt 1.2.8 |
Discussion
MantisBT Multiple Local File Include and Cross Site Scripting Vulnerabilities
MantisBT is prone to multiple local file-include and cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker can exploit the local file-include vulnerabilities using directory-traversal strings to view and execute local files within the context of the webserver process. Information harvested may aid in further attacks.
The attacker may leverage the cross-site scripting issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
MantisBT versions prior to 1.2.8 are vulnerable.
MantisBT is prone to multiple local file-include and cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker can exploit the local file-include vulnerabilities using directory-traversal strings to view and execute local files within the context of the webserver process. Information harvested may aid in further attacks.
The attacker may leverage the cross-site scripting issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
MantisBT versions prior to 1.2.8 are vulnerable.
Exploit / POC
MantisBT Multiple Local File Include and Cross Site Scripting Vulnerabilities
Attackers can exploit these issues using a browser. To exploit cross-site scripting issues, attackers must entice an unsuspecting user to follow a malicious URI.
Please see the references for example URIs.
Attackers can exploit these issues using a browser. To exploit cross-site scripting issues, attackers must entice an unsuspecting user to follow a malicious URI.
Please see the references for example URIs.
Solution / Fix
MantisBT Multiple Local File Include and Cross Site Scripting Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
MantisBT Multiple Local File Include and Cross Site Scripting Vulnerabilities
References:
References:
- 0013191: XSS vulnerability dues to usage of PHP_SELF (MantisBT Group)
- 0013281: MantisBT Security Vulnerabilities Notification (MantisBT Group)
- LFI and XSS via bug_actiongroup_ext_page.php (openwall)
- mantisbt-1.2.8 multiple vulnerabilities (1xLFI+XSS, 2xXSS) (openwall)
- Multiple vulnerabilities in MantisBT (High-Tech Bridge )
- Vendor Homepage (MantisBT)
- [SECURITY] [DSA 2308-1] mantis security update (Debian)
- Potential Security Vulnerabilities in Oracle Java 5 SDK affecting IBM WebSphere (\IBM)