Show filters
164 Total Results
Displaying 121-130 of 164
Sort by:
Attacker Value
Unknown
CVE-2008-4688
Disclosure Date: October 22, 2008 (last updated October 04, 2023)
core/string_api.php in Mantis before 1.1.3 does not check the privileges of the viewer before composing a link with issue data in the source anchor, which allows remote attackers to discover an issue's title and status via a request with a modified issue number.
0
Attacker Value
Unknown
CVE-2008-4687
Disclosure Date: October 22, 2008 (last updated October 04, 2023)
manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort parameter containing PHP sequences, which are processed by create_function within the multi_sort function in core/utility_api.php.
0
Attacker Value
Unknown
CVE-2008-4689
Disclosure Date: October 22, 2008 (last updated October 04, 2023)
Mantis before 1.1.3 does not unset the session cookie during logout, which makes it easier for remote attackers to hijack sessions.
0
Attacker Value
Unknown
CVE-2008-3102
Disclosure Date: September 24, 2008 (last updated October 04, 2023)
Mantis 1.1.x through 1.1.2 and 1.2.x through 1.2.0a2 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
0
Attacker Value
Unknown
CVE-2008-3331
Disclosure Date: July 27, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in return_dynamic_filters.php in Mantis before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the filter_target parameter.
0
Attacker Value
Unknown
CVE-2008-3332
Disclosure Date: July 27, 2008 (last updated October 04, 2023)
Eval injection vulnerability in adm_config_set.php in Mantis before 1.1.2 allows remote authenticated administrators to execute arbitrary code via the value parameter.
0
Attacker Value
Unknown
CVE-2008-3333
Disclosure Date: July 27, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in core/lang_api.php in Mantis before 1.1.2 allows remote attackers to include and execute arbitrary files via the language parameter to the user preferences page (account_prefs_update.php).
0
Attacker Value
Unknown
CVE-2008-0404
Disclosure Date: January 23, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Mantis before 1.1.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to the "Most active bugs" summary.
0
Attacker Value
Unknown
CVE-2007-6611
Disclosure Date: January 03, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in view.php in Mantis before 1.1.0 allows remote attackers to inject arbitrary web script or HTML via a filename, related to bug_report.php.
0
Attacker Value
Unknown
CVE-2006-6574
Disclosure Date: December 15, 2006 (last updated October 04, 2023)
Mantis before 1.1.0a2 does not implement per-item access control for Issue History (Bug History), which allows remote attackers to obtain sensitive information by reading the Change column, as demonstrated by the Change column of a custom field.
0