Skip to main content
Medium CVE-2011-3356 September 13, 2011

PHP Self Cross Site Scripting in MantisBT 1.2.x

MantisBT installations 1.2.x up to 1.2.7 are vulnerable to Cross Site Scripting attacks due to lack of sanitation of the variable $_SERVER["PHP_SELF"]

CVSS Score

6.1 / 10.0

Severity

Medium

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Advisory

ApplicationMantisBT
Affected Versions1.2.2 through 1.2.7
Fixed In1.2.8
CVECVE-2011-3356
Websec AdvisoryWS11-16

Background

MantisBT is a web-based bug tracker written in PHP. It runs on Windows, Linux, macOS, and other platforms and supports MySQL, MS SQL, and PostgreSQL.

Description

The PHP variable $_SERVER["PHP_SELF"] is written into HTML output without sanitization across several files. An attacker who can convince a victim to click a crafted MantisBT URL can inject script into the response, leading to stored or reflected XSS depending on the entry point.

Remediation

Upgrade MantisBT to 1.2.8 or later.

Share this advisory:

Related Security Advisories

Stay informed about other recent vulnerabilities and security advisories

Critical December 18, 2014

Command Execution and Backdoor in Zhone GPON-2520

This post will describe a backdoor account found in the Zhone GPON-2520 and will provide a PoC which can be used to disable the firewall filtration rules in order to allow access to services such as ssh, telnet and ftp.

Severity:
CVSS: 9.8
View advisory
High May 22, 2014

Huawei HG8245 / HG8247 WPA Generator

Huawei HG8245 & HG8247 ONT (firmware version V1R006C00S100) rely on a weak algorithm to calculate the WPA keys, keys can be predicted easily using the WiFi's MAC Address (BSSID).

Severity:
CVSS: 7.4
View advisory
High December 19, 2013

Arbitrary Command Execution in Alcatel-Lucent I-240W-Q

The Alcatel-Lucent I-240W-Q ONT's Diagnostics page does not filter shell metacharacters in the IP address field, allowing any authenticated administrator to execute arbitrary commands as root and fully compromise the device.

Severity:
CVSS: 8.0
View advisory