4.3
CVSSv2

CVE-2011-3358

Published: 21/09/2011 Updated: 09/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in MantisBT prior to 1.2.8 allow remote malicious users to inject arbitrary web script or HTML via the (1) os, (2) os_build, or (3) platform parameter to (a) bug_report_page.php or (b) bug_update_advanced_page.php, related to use of the Projax library.

Vulnerable Product Search on Vulmon Subscribe to Product

mantisbt mantisbt 1.0.3

mantisbt mantisbt 1.1.2

mantisbt mantisbt 1.0.8

mantisbt mantisbt 1.1.8

mantisbt mantisbt 1.2.2

mantisbt mantisbt 1.2.5

mantisbt mantisbt 1.2.6

mantisbt mantisbt 1.0.2

mantisbt mantisbt 1.0.1

mantisbt mantisbt 1.1.0

mantisbt mantisbt 1.0.6

mantisbt mantisbt 1.2.0

mantisbt mantisbt 1.1.6

mantisbt mantisbt

mantisbt mantisbt 0.19.3

mantisbt mantisbt 1.1.1

mantisbt mantisbt 1.0.5

mantisbt mantisbt 1.2.1

mantisbt mantisbt 1.2.3

mantisbt mantisbt 1.2.4

mantisbt mantisbt 1.0.0

mantisbt mantisbt 0.19.4

mantisbt mantisbt 1.0.7

mantisbt mantisbt 1.0.4

mantisbt mantisbt 1.1.7

mantisbt mantisbt 1.1.4

mantisbt mantisbt 1.1.5

Vendor Advisories

Several vulnerabilities were found in Mantis, a web-based bug tracking system: Insufficient input validation could result in local file inclusion and cross-site scripting For the oldstable distribution (lenny), this problem has been fixed in version 116+dfsg-2lenny6 For the stable distribution (squeeze), this problem has been fixed in version 1 ...