Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Gentoo Linux Security Advisory GLSA 200803-04
https://security.gentoo.org/
Severity: Low
Title: Mantis: Cross-Site Scripting
Date: March 03, 2008
Bugs: #203791
ID: 200803-04
Synopsis
=======
A persistent Cross-Site Scripting vulnerability has been discovered in
Mantis.
Background
=========
Mantis is a web-based bug tracking system.
Affected packages
================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 www-apps/mantisbt < 1.0.8-r1 >= 1.0.8-r1
==========
seiji reported that the filename for the uploaded file in
bug_report.php is not properly sanitised before being stored.
Impact
=====
A remote attacker could upload a file with a specially ...Read the Full Advisory
style>.gentoo_availability{display:block;}
Get the latest Linux and open source security news straight to your inbox.