Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown
CVE-2014-9269
Disclosure Date: January 09, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in helper_api.php in MantisBT 1.1.0a1 through 1.2.x before 1.2.18, when Extended project browser is enabled, allows remote attackers to inject arbitrary web script or HTML via the project cookie.
0
Attacker Value
Unknown
CVE-2014-8554
Disclosure Date: November 13, 2014 (last updated October 05, 2023)
SQL injection vulnerability in the mc_project_get_attachments function in api/soap/mc_project_api.php in MantisBT before 1.2.18 allows remote attackers to execute arbitrary SQL commands via the project_id parameter. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1609.
0
Attacker Value
Unknown
CVE-2012-1118
Disclosure Date: June 29, 2012 (last updated October 04, 2023)
The access_has_bug_level function in core/access_api.php in MantisBT before 1.2.9 does not properly restrict access when the private_bug_view_threshold is set to an array, which allows remote attackers to bypass intended restrictions and perform certain operations on private bug reports.
0
Attacker Value
Unknown
CVE-2012-1122
Disclosure Date: June 29, 2012 (last updated October 04, 2023)
bug_actiongroup.php in MantisBT before 1.2.9 does not properly check the report_bug_threshold permission of the receiving project when moving a bug report, which allows remote authenticated users with the report_bug_threshold and move_bug_threshold privileges for a project to bypass intended access restrictions and move bug reports to a different project.
0
Attacker Value
Unknown
CVE-2008-3102
Disclosure Date: September 24, 2008 (last updated October 04, 2023)
Mantis 1.1.x through 1.1.2 and 1.2.x through 1.2.0a2 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
0