Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <AANLkTin=pn9EU2U2JzBTjyuhtos3Bb9+UocMkX+MJs_+@mail.gmail.com>
Date: Tue, 14 Sep 2010 17:05:02 -0600
From: Kurt Seifried <kurt@...fried.org>
To: oss-security@...ts.openwall.com
Subject: Re: CVE request: mantis before 1.2.3 (XSS)

On Tue, Sep 14, 2010 at 3:06 PM, Hanno Böck <hanno@...eck.de> wrote:
> From release notes
>
> "Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library.
> The fix has been applied to the library included in MantisBT releases,
> and a patch has been submitted upstream for future releases of NuSOAP.
> See http://www.mantisbt.org/bugs/view.php?id=12312 for further details.

Are you talking about the PHP_SELF thing?
http://sourceforge.net/projects/nusoap/forums/forum/193579/topic/3834005
https://bugzilla.redhat.com/show_bug.cgi?id=629585
if so it has a CVE #:
CVE-2010-3070 php-nusoap: XSS vulnerability due improper escaping of URLs

-- 
Kurt Seifried
kurt@...fried.org
tel: 1-703-879-3176

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.