Show filters
29 Total Results
Displaying 11-20 of 29
Sort by:
Attacker Value
Unknown

CVE-2006-0665

Disclosure Date: February 13, 2006 (last updated February 22, 2025)
Unspecified vulnerability in (1) query_store.php and (2) manage_proj_create.php in Mantis before 1.0.0 has unknown impact and attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. An original vendor bug report is referenced, but not accessible to the general public.
0
Attacker Value
Unknown

CVE-2006-0147

Disclosure Date: January 09, 2006 (last updated February 22, 2025)
Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PhpOpenChat, possibly (7) MAXdev MD-Pro, and (8) Simplog, allows remote attackers to execute arbitrary PHP functions via the do parameter, which is saved in a variable that is then executed as a function, as demonstrated using phpinfo.
0
Attacker Value
Unknown

CVE-2006-0146

Disclosure Date: January 09, 2006 (last updated February 22, 2025)
The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MAXdev MD-Pro, and (8) MediaBeez, when the MySQL root password is empty, allows remote attackers to execute arbitrary SQL commands via the sql parameter.
0
Attacker Value
Unknown

CVE-2005-4523

Disclosure Date: December 28, 2005 (last updated February 22, 2025)
Mantis 1.0.0rc3 and earlier discloses private bugs via public RSS feeds, which allows remote attackers to obtain sensitive information.
0
Attacker Value
Unknown

CVE-2005-4519

Disclosure Date: December 28, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in the manage user page (manage_user_page.php) in Mantis 1.0.0rc3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) prefix and (2) sort parameters to the manage user page (manage_user_page.php), or (3) the sort parameter to view_all_set.php.
0
Attacker Value
Unknown

CVE-2005-4238

Disclosure Date: December 14, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in view_filters_page.php in Mantis 1.0.0rc3 and earlier allows remote attackers to inject arbitrary web script or HTML via the target_field parameter.
0
Attacker Value
Unknown

CVE-2005-3336

Disclosure Date: October 27, 2005 (last updated February 22, 2025)
SQL injection vulnerability in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
0
Attacker Value
Unknown

CVE-2005-3338

Disclosure Date: October 27, 2005 (last updated February 22, 2025)
Unspecified vulnerability in Mantis before 0.19.3, when using reminders, causes Mantis to display the real email addresses of users.
0
Attacker Value
Unknown

CVE-2005-3335

Disclosure Date: October 27, 2005 (last updated February 22, 2025)
PHP file inclusion vulnerability in bug_sponsorship_list_view_inc.php in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbitrary PHP code and include arbitrary local files via the t_core_path parameter.
0
Attacker Value
Unknown

CVE-2005-3339

Disclosure Date: October 27, 2005 (last updated February 22, 2025)
Mantis before 0.19.3 caches the User ID longer than necessary, which has unknown impact and attack vectors.
0