CVE-2011-3357
https://notcve.org/view.php?id=CVE-2011-3357
Directory traversal vulnerability in bug_actiongroup_ext_page.php in MantisBT before 1.2.8 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the action parameter, related to bug_actiongroup_page.php. Vulnerabilidad de salto de directorio en bug_actiongroup_ext_page.php en MantisBT antes de v1.2.8, permite a atacantes remotos incluir y ejecutar archivos locales de su elección a través del parámetro .. (punto punto) en el parámetro action, relacionado con bug_actiongroup_page.php. • http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=640297 http://lists.debian.org/debian-security-tracker/2011/09/msg00012.html http://lists.fedoraproject.org/pipermail/package-announce/2011-September/066061.html http://secunia.com/advisories/45961 http://secunia.com/advisories/51199 http://security.gentoo.org/glsa/glsa-201211-01.xml http://securityreason.com/securityalert/8392 http://www.debian.org/security/2011/dsa-2308 http://www.mantisbt.org/bugs/view.php?id=13281 http://www • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2011-3358
https://notcve.org/view.php?id=CVE-2011-3358
Multiple cross-site scripting (XSS) vulnerabilities in MantisBT before 1.2.8 allow remote attackers to inject arbitrary web script or HTML via the (1) os, (2) os_build, or (3) platform parameter to (a) bug_report_page.php or (b) bug_update_advanced_page.php, related to use of the Projax library. Múltiples vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados (XSS) en MantisBT antes de v1.2.8, permite a atacantes remotos inyectar secuencias de comandos web o HTML a través del parámetro (1) os, (2) os_build, (3) platform de (a) bug_report_page.php o (b) bug_update_advanced_page.php, relacionado con el uso de la librería Projax • http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=640297 http://lists.debian.org/debian-security-tracker/2011/09/msg00012.html http://lists.fedoraproject.org/pipermail/package-announce/2011-September/066061.html http://secunia.com/advisories/45961 http://secunia.com/advisories/51199 http://security.gentoo.org/glsa/glsa-201211-01.xml http://securityreason.com/securityalert/8392 http://www.debian.org/security/2011/dsa-2308 http://www.openwall.com/lists/oss-security/2011/09/04/1 htt • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •