Bug#640297: XSS vulnerability dues to usage of PHP_SELF : Not fixed

2011-09-05 Thread sils
again :-) BTW in debian package versions < 1.2.x (debian stable, old stable), all these bugs are not applicable, I'm going to create the needed ones, If I have some troubles I will ask for some help, if you don't mind, of course. Thanks a lot, really. Great job Team! Cheers, Sil

Bug#640297: XSS vulnerability dues to usage of PHP_SELF : Not fixed

2011-09-05 Thread sils
about this, but I need to know the implications or which is the best option. Thanks a lot for your help. Regards, Sils [1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=640297 [2] http://www.mantisbt.org/bugs/view.php?id=13191 [3] https://github.com/mantisbt/mantisbt/commit/d00745f5e267eba4ca34286

Bug#638321: MantisBT <1.2.7 search.php multiple XSS vulnerabilities

2011-08-18 Thread sils
. Best regards, Sils [1] http://anonscm.debian.org/gitweb/?p=collab-maint/mantis.git;a=commit;h=6f1499b9623acab6b89ee940d4af54dcff746b44 signature.asc Description: OpenPGP digital signature

Bug#607159: MantisBT <1.2.4 multiple vulnerabilities (LFI, XSS and PD)

2010-12-15 Thread sils
t, at all. That's another reason because it's not accessible|blocked from our distributed version. The application of the patch made sence because we distribute the upstream source code, but it is useless for mantis package installed in debian. Thanks all of you, again. Best Regards, Si

Bug#595510: mantis: CVE-2010-2574 xss vulnerability

2010-09-04 Thread sils
found 595510 1.1.8+dfsg-5 found 595510 1.1.6+dfsg-2lenny1 forwarded 595510 http://www.mantisbt.org/bugs/view.php?id=12230 tag 595510 +patch thanks Hi all, Sorry, it was a misunderstanding. As referenced in [0], reported by Secunia, SA40832 [1] (which refers to (CVE-2010-2574 [2]), there is an XS

Bug#595510: mantis: CVE-2010-2574 xss vulnerability

2010-09-04 Thread sils
version 595510 1.2.x forwarded 595510 http://www.mantisbt.org/bugs/view.php?id=12312 thanks Hi, I tested this issue under version 1.1.6+dfsg-2lenny1 (lenny), 1.1.8+dfsg-5 (sid) and 1.2.1-1 (being packaged, soon in experimental), so I am reassigning this issue to version 1.2.x This bug does not