Summary
The remote web server contains a PHP application that is prone to cross-site scripting attacks.
Description :
According to its banner, the remote version of Mantis contains a flaw in the handling of some types of input. Because of this, an attacker may be able to cause arbitrary HTML and script code to be executed in a user's browser within the security context of the affected web site.
Solution
Upgrade to Mantis 0.18.1 or newer.
References
Updated on 2015-03-25
Severity
Classification
-
CVSS Base Score: 4.3
AV:N/AC:M/Au:N/C:N/I:P/A:N
Related Vulnerabilities
- Apache Roller 'q' Parameter Cross Site Scripting Vulnerability
- Apache Tomcat cal2.jsp Cross Site Scripting Vulnerability
- Adobe JRun Management Console Multiple Vulnerabilities
- Apache Open For Business HTML injection vulnerability
- Aardvark Topsites PHP 'index.php' Multiple Cross Site Scripting Vulnerabilities