CVE-2010-3070

Cross-site scripting (XSS) vulnerability in NuSOAP 0.9.5, as used in MantisBT and other products, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to an arbitrary PHP script that uses NuSOAP classes.

Date published : 2010-09-28

http://www.securityfocus.com/bid/42959

http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=595248