Summary
The remote web server contains a PHP application that is prone to cross-site scripting attacks.
Description :
According to its banner, the remote version of Mantis contains a flaw in the handling of some types of input. Because of this, an attacker may be able to cause arbitrary HTML and script code to be executed in a user's browser within the security context of the affected web site.
Solution
Upgrade to Mantis 0.18.1 or newer.
References
Updated on 2015-03-25
Severity
Classification
-
CVSS Base Score: 4.3
AV:N/AC:M/Au:N/C:N/I:P/A:N
Related Vulnerabilities
- Apache ActiveMQ Persistent Cross-Site Scripting Vulnerability
- Adobe Presenter viewer.swf and loadflash.js XSS Vulnerability
- Apache Commons Daemon 'jsvc' Information Disclosure Vulnerability
- Apache ActiveMQ 'admin/queueBrowse' Cross Site Scripting Vulnerability
- AdaptCMS 'init.php' Remote File Include Vulnerability