Back to search
CVE-2010-2574
Published: Aug 9, 2010
Modified: Aug 7, 2024
PUBLISHED
Description
Cross-site scripting (XSS) vulnerability in manage_proj_cat_add.php in MantisBT 1.2.2 allows remote authenticated administrators to inject arbitrary web script or HTML via the name parameter in an Add Category action.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://secunia.com/secunia_research/2010-103/
x_refsource_MISC
FEDORA-2010-15080
vendor-advisory
x_refsource_FEDORA
FEDORA-2010-15082
vendor-advisory
x_refsource_FEDORA
41653
third-party-advisory
x_refsource_SECUNIA
ADV-2010-2535
vdb-entry
x_refsource_VUPEN
40832
third-party-advisory
x_refsource_SECUNIA
[oss-security] 20100914 CVE request: mantis before 1.2.3 (XSS)
mailing-list
x_refsource_MLIST
20100805 Secunia Research: MantisBT "Add Category" Script Insertion Vulnerability
mailing-list
x_refsource_BUGTRAQ
FEDORA-2010-15061
vendor-advisory
x_refsource_FEDORA
[oss-security] 20100914 Re: CVE request: mantis before 1.2.3 (XSS)
mailing-list
x_refsource_MLIST
http://www.mantisbt.org/bugs/changelog_page.php?version_id=111
x_refsource_CONFIRM
http://www.mantisbt.org/bugs/view.php?id=12230
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now