Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Tue, 14 Sep 2010 17:05:02 -0600
From: Kurt Seifried <>
Subject: Re: CVE request: mantis before 1.2.3 (XSS)

On Tue, Sep 14, 2010 at 3:06 PM, Hanno Böck <> wrote:
> From release notes
> "Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library.
> The fix has been applied to the library included in MantisBT releases,
> and a patch has been submitted upstream for future releases of NuSOAP.
> See for further details.

Are you talking about the PHP_SELF thing?
if so it has a CVE #:
CVE-2010-3070 php-nusoap: XSS vulnerability due improper escaping of URLs

Kurt Seifried
tel: 1-703-879-3176

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.