Mantis Bug Tracker

View Issue Details Jump to Notes ]
IDProjectCategoryView StatusLast Update
0000427ForumApispublic2008-09-22 15:54
Reporteradministrator 
Assigned Toadministrator 
PrioritynormalSeverityminorReproducibilityhave not tried
StatusresolvedResolutionfixed 
PlatformOSOS Version
Product Version0.6.7 
Target Version0.6.8Fixed in Version0.6.8 
Summary0000427: Security issue on item_add
DescriptionThere is a security hole in the item_add procedure and in the post_item procedure.

User that do not get the privilege to create item on the forum can attach vote and some other stuff
TagsNo tags attached.
Attached Files

- Relationships
child of 0000424resolvedadministrator Add the item_add procedure to the apis package 

-  Notes
~0001147
administrator (administrator)


Fixed

- Issue History
Date Modified Username Field Change
2008-09-22 15:54 administrator New Issue
2008-09-22 15:54 administrator Status new => assigned
2008-09-22 15:54 administrator Assigned To => administrator
2008-09-22 15:54 administrator Relationship added child of 0000424
2008-09-22 15:54 administrator Note Added: 0001147
2008-09-22 15:54 administrator Status assigned => resolved
2008-09-22 15:54 administrator Fixed in Version => 0.6.8
2008-09-22 15:54 administrator Resolution open => fixed