Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Debian Local Security Checks >> [DSA1133] DSA-1133-1 mantis


Vulnerability Assessment Details

[DSA1133] DSA-1133-1 mantis

Vulnerability Assessment Summary
DSA-1133-1 mantis

Detailed Explanation for this Vulnerability Assessment

Several remote vulnerabilities have been discovered in the Mantis bug
tracking system, which may lead to the execution of arbitrary web script.
The Common Vulnerabilities and Exposures project identifies the following
problems:
A cross-site scripting vulnerability was discovered in
config_defaults_inc.php.
Cross-site scripting vulnerabilities were discovered in query_store.php
and manage_proj_create.php.
Multiple cross-site scripting vulnerabilities were discovered in
view_all_set.php, manage_user_page.php, view_filters_page.php and
proj_doc_delete.php.
Multiple cross-site scripting vulnerabilities were discovered in
view_all_set.php.
For the stable distribution (sarge) these problems have been fixed in
version 0.19.2-5sarge4.1.
For the unstable distribution (sid) these problems have been fixed in
version 0.19.4-3.1.
We recommend that you upgrade your mantis package.


Solution : http://www.debian.org/security/2006/dsa-1133
Network Security Threat Level: High

Networks Security ID:

Vulnerability Assessment Copyright: This script is (C) 2007 Michel Arboi

Cables, Connectors

Dymo LabelWriter Print Server 1750630
$95.95
Dymo LabelWriter Print Server 1750630 pictureHP 399052-001 012925-001 336091-002 MSA60 Server Fan Module Complete & Tested
$40.32
HP 399052-001 012925-001 336091-002 MSA60 Server Fan Module Complete & Tested picture146.8GB IBM Server 39R7350 26K5842 40K1044 3.5" SAS 10K Hard Drive with Caddy
$58.41
146.8GB IBM Server 39R7350 26K5842 40K1044 3.5Belkin Omniview SMB F1DP101A-AU (Server Interface Module) USB - RJ45 - VGA
$55.62
Belkin Omniview SMB F1DP101A-AU (Server Interface Module) USB - RJ45 - VGA picture


Discussions

No Discussions have been posted on this vulnerability.