LWN.net Logo

mantis: missing input sanitizing

Package(s):mantis CVE #(s):CAN-2005-2556 CAN-2005-2557
Created:August 19, 2005 Updated:September 26, 2005
Description: Two security related problems have been discovered in Mantis, a web-based bug tracking system. A remote attacker could insert arbitrary SQL code into SQL statements and a remote attacker was able to insert arbitrary HTML code bug reports, hence, cross site scripting.
Alerts:
Gentoo 200509-16 2005-09-24
Debian DSA-778-1 2005-08-19

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds