Cross-site scripting (XSS) vulnerability in file_download.php in MantisBT before 1.2.18 allows remote authenticated users to inject arbitrary web script or HTML via a Flash file with an image extension, related to inline attachments, as demonstrated by a .swf.jpeg filename.
References
Link Resource
http://seclists.org/oss-sec/2014/q4/867 Mailing List Third Party Advisory
http://seclists.org/oss-sec/2014/q4/902 Mailing List Third Party Advisory
http://seclists.org/oss-sec/2014/q4/924 Mailing List Third Party Advisory
http://secunia.com/advisories/62101 Third Party Advisory
http://www.debian.org/security/2015/dsa-3120 Third Party Advisory
https://github.com/mantisbt/mantisbt/commit/9fb8cf36f Patch Third Party Advisory
https://www.mantisbt.org/bugs/view.php?id=17874 Exploit Issue Tracking Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2015-01-09T18:00:00

Updated: 2016-12-30T16:57:01

Reserved: 2014-12-04T00:00:00


Link: CVE-2014-9271

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2015-01-09T18:59:02.587

Modified: 2021-03-04T20:30:55.123


Link: CVE-2014-9271

JSON object: View

cve-icon Redhat Information

No data.

CWE