Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Gentoo: GLSA-200509-16 Normal: Mantis SQL Injection And XSS Threats

gentoo
Calendar Grey September 24, 2005
Scroller Gentoo
Recent assessments have unveiled severe vulnerabilities related to SQL injection and XSS in Mantis. A software patch is necessary to fortify the security of Gentoo Linux installations.
Mantis is affected by an SQL injection and several cross-site scripting (XSS) vulnerabilities.

Summary

Gentoo Linux Security Advisory GLSA 200509-16 https://security.gentoo.org/ Severity: Normal Title: Mantis: XSS and SQL injection vulnerabilities Date: September 24, 2005 Bugs: #103308 ID: 200509-16

Synopsis ======= Mantis is affected by an SQL injection and several cross-site scripting (XSS) vulnerabilities.
Background ========= Mantis is a web-based bugtracking system written in PHP.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-apps/mantisbt < 0.19.2 >= 0.19.2
========== Mantis fails to properly sanitize untrusted input before using it. This leads to an SQL injection and several cross-site scripting vulnerabilities.
Impact ===== An attacker could p...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround