Date: Tue, 14 Sep 2010 17:05:02 -0600 From: Kurt Seifried <kurt@...fried.org> To: oss-security@...ts.openwall.com Subject: Re: CVE request: mantis before 1.2.3 (XSS) On Tue, Sep 14, 2010 at 3:06 PM, Hanno Böck <hanno@...eck.de> wrote: > From release notes > > "Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. > The fix has been applied to the library included in MantisBT releases, > and a patch has been submitted upstream for future releases of NuSOAP. > See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Are you talking about the PHP_SELF thing? http://sourceforge.net/projects/nusoap/forums/forum/193579/topic/3834005 https://bugzilla.redhat.com/show_bug.cgi?id=629585 if so it has a CVE #: CVE-2010-3070 php-nusoap: XSS vulnerability due improper escaping of URLs -- Kurt Seifried kurt@...fried.org tel: 1-703-879-3176
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.