![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2010-2802 |
Description: | Cross-site scripting (XSS) vulnerability in MantisBT before 1.2.2 allows remote authenticated users to inject arbitrary web script or HTML via an HTML document with a .gif filename extension, related to inline attachments. |
Test IDs: | None available |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2010-2802 [oss-security] 20100803 CVE request: Attachment XSS in mantis < 1.2.2 http://www.openwall.com/lists/oss-security/2010/08/02/16 [oss-security] 20100803 Re: CVE request: Attachment XSS in mantis < 1.2.2 http://www.openwall.com/lists/oss-security/2010/08/03/7 http://www.mantisbt.org/blog/?p=113 http://www.mantisbt.org/blog/?p=113 http://www.mantisbt.org/bugs/view.php?id=11952 http://www.mantisbt.org/bugs/view.php?id=11952 https://bugzilla.redhat.com/show_bug.cgi?id=620992 https://bugzilla.redhat.com/show_bug.cgi?id=620992 |