Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Thu, 16 Dec 2010 08:58:34 -0500 (EST)
From: Josh Bressers <>
Cc: coley <>
Subject: Re: CVE request: MantisBT <=1.2.3 (db_type)
 Cross-Site Scripting & Path Disclosure Vulnerability

Please use CVE-2010-4348 for the XSS.
CVE-2010-4349 for the path disclosure.



----- "David Hicks" <> wrote:

> This is a CVE request for a vulnerability discovered in MantisBT
> <1.2.4
> by Gjoko Krstic of Zero Science Lab as per the following advisory:
> MantisBT 1.2.4 has been released to resolve this issue.
> For distributions or users using MantisBT 1.1.x, the following patch
> can
> be applied:
> Please note that MantisBT 1.1.x is not recommended for use due to
> many
> security improvements and features implemented in MantisBT 1.2.x (but
> not backported to 1.1.x).
> Detailed information about this vulnerability can be found in this
> bug
> report:
> Regards,
> David Hicks
> MantisBT Developer
>, #mantishelp freenode

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ