MantisBT 'projax_api.php' HTML Injection Vulnerability
BID:71372
Info
MantisBT 'projax_api.php' HTML Injection Vulnerability
| Bugtraq ID: | 71372 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-9270 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 01 2014 12:00AM |
| Updated: | Jan 12 2015 01:01AM |
| Credit: | Offensive Security |
| Vulnerable: |
Mantisbt Mantisbt 1.2.9 Mantisbt Mantisbt 1.2.8 Mantisbt Mantisbt 1.2.7 Mantisbt Mantisbt 1.2.6 Mantisbt Mantisbt 1.2.4 Mantisbt Mantisbt 1.2.3 Mantisbt Mantisbt 1.1.8 Mantisbt Mantisbt 1.1.7 Mantisbt Mantisbt 1.1.5 Mantisbt Mantisbt 1.2.2 Mantisbt Mantisbt 1.2.1 Mantisbt Mantisbt 1.1.6 Mantisbt Mantisbt 1.1.4 Mantisbt Mantisbt 1.1.2 Mantisbt Mantisbt 1.1.1 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: | |
Discussion
MantisBT 'projax_api.php' HTML Injection Vulnerability
MantisBT is prone to a HTML-injection vulnerability because it fails to properly sanitize user-supplied data.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
MantisBT versions 1.1.0a3 through 1.2.17are vulnerable.
MantisBT is prone to a HTML-injection vulnerability because it fails to properly sanitize user-supplied data.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
MantisBT versions 1.1.0a3 through 1.2.17are vulnerable.
Exploit / POC
MantisBT 'projax_api.php' HTML Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
MantisBT 'projax_api.php' HTML Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
MantisBT 'projax_api.php' HTML Injection Vulnerability
References:
References: