Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2014-9272
Description:The string_insert_href function in MantisBT 1.2.0a1 through 1.2.x before 1.2.18 does not properly validate the URL protocol, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the javascript:// protocol.
Test IDs: 1.3.6.1.4.1.25623.1.0.805976   1.3.6.1.4.1.25623.1.0.805975  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2014-9272
Debian Security Information: DSA-3120 (Google Search)
http://www.debian.org/security/2015/dsa-3120
http://seclists.org/oss-sec/2014/q4/867
http://seclists.org/oss-sec/2014/q4/902
http://secunia.com/advisories/62101




© 1998-2025 E-Soft Inc. All rights reserved.