4.3
CVSSv2

CVE-2011-2938

Published: 21/09/2011 Updated: 27/08/2013
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in filter_api.php in MantisBT prior to 1.2.7 allow remote malicious users to inject arbitrary web script or HTML via a parameter, as demonstrated by the project_id parameter to search.php.

Vulnerable Product Search on Vulmon Subscribe to Product

mantisbt mantisbt 1.1.1

mantisbt mantisbt 1.1.2

mantisbt mantisbt 1.1.8

mantisbt mantisbt 1.2.2

mantisbt mantisbt 1.2.4

mantisbt mantisbt 1.2.5

mantisbt mantisbt 1.0.3

mantisbt mantisbt 1.0.2

mantisbt mantisbt 1.0.8

mantisbt mantisbt 1.1.0

mantisbt mantisbt 1.0.6

mantisbt mantisbt 1.2.0

mantisbt mantisbt 1.1.6

mantisbt mantisbt

mantisbt mantisbt 0.19.4

mantisbt mantisbt 0.19.3

mantisbt mantisbt 1.0.5

mantisbt mantisbt 1.2.1

mantisbt mantisbt 1.1.5

mantisbt mantisbt 1.2.3

mantisbt mantisbt 1.0.1

mantisbt mantisbt 1.0.0

mantisbt mantisbt 1.0.7

mantisbt mantisbt 1.0.4

mantisbt mantisbt 1.1.7

mantisbt mantisbt 1.1.4

Exploits

source: wwwsecurityfocuscom/bid/49235/info MantisBT is prone to an SQL-injection vulnerability and a cross-site scripting vulnerability Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying d ...