View Issue Details

IDProjectCategoryView StatusLast Update
0006509mantisbtsecuritypublic2006-10-09 11:55
Reporterthraxisp Assigned Tothraxisp  
PrioritynormalSeverityminorReproducibilityalways
Status closedResolutionfixed 
Product Version1.0.0rc4 
Fixed in Version1.0.0rc5 
Summary0006509: Port: Additional XSS Vulnerabilities in Filter
Description

Some XSS vulnerabilities in the filter were missed in the last patch.

GET: ?type=1&highlight_changed=[XSS]
GET: ?type=1&relationship_type=[XSS]
GET: ?type=1&relationship_bug=[XSS]

Originally reported by Thomas Waldegger thomas.waldegger@morph3us.org

TagsNo tags attached.

Relationships

child of 0006508 closedthraxisp Additional XSS Vulnerabilities in Filter 

Activities

thraxisp

thraxisp

2005-12-18 09:23

reporter   ~0011812

Fixed in CVS.

on BRANCH_1_0_0rc4
view_all_set.php -> 1.57.4.1.2.1
core/filter_api.php -> 1.122.2.2.2.3.2.1