Show filters
17 Total Results
Displaying 1-10 of 17
Sort by:
Attacker Value
Unknown
CVE-2013-1931
Disclosure Date: October 31, 2019 (last updated November 27, 2024)
A cross-site scripting (XSS) vulnerability in MantisBT 1.2.14 allows remote attackers to inject arbitrary web script or HTML via a version, related to deleting a version.
0
Attacker Value
Unknown
CVE-2015-2046
Disclosure Date: August 28, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in MantisBT 1.2.13 and later before 1.2.20.
0
Attacker Value
Unknown
CVE-2014-8987
Disclosure Date: August 24, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the "set configuration" box in the Configuration Report page (adm_config_report.php) in MantisBT 1.2.13 through 1.2.17 allows remote administrators to inject arbitrary web script or HTML via the config_option parameter, a different vulnerability than CVE-2014-8986.
0
Attacker Value
Unknown
CVE-2015-1042
Disclosure Date: February 10, 2015 (last updated October 05, 2023)
The string_sanitize_url function in core/string_api.php in MantisBT 1.2.0a3 through 1.2.18 uses an incorrect regular expression, which allows remote attackers to conduct open redirect and phishing attacks via a URL with a ":/" (colon slash) separator in the return parameter to login_page.php, a different vulnerability than CVE-2014-6316.
0
Attacker Value
Unknown
CVE-2014-9271
Disclosure Date: January 09, 2015 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in file_download.php in MantisBT before 1.2.18 allows remote authenticated users to inject arbitrary web script or HTML via a Flash file with an image extension, related to inline attachments, as demonstrated by a .swf.jpeg filename.
0
Attacker Value
Unknown
CVE-2014-9269
Disclosure Date: January 09, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in helper_api.php in MantisBT 1.1.0a1 through 1.2.x before 1.2.18, when Extended project browser is enabled, allows remote attackers to inject arbitrary web script or HTML via the project cookie.
0
Attacker Value
Unknown
CVE-2014-9272
Disclosure Date: January 09, 2015 (last updated October 05, 2023)
The string_insert_href function in MantisBT 1.2.0a1 through 1.2.x before 1.2.18 does not properly validate the URL protocol, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the javascript:// protocol.
0
Attacker Value
Unknown
CVE-2014-9270
Disclosure Date: December 08, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the projax_array_serialize_for_autocomplete function in core/projax_api.php in MantisBT 1.1.0a3 through 1.2.17 allows remote attackers to inject arbitrary web script or HTML via the "profile/Platform" field.
0
Attacker Value
Unknown
CVE-2014-9279
Disclosure Date: December 08, 2014 (last updated October 05, 2023)
The print_test_result function in admin/upgrade_unattended.php in MantisBT 1.1.0a3 through 1.2.x before 1.2.18 allows remote attackers to obtain database credentials via a URL in the hostname parameter and reading the parameters in the response sent to the URL.
0
Attacker Value
Unknown
CVE-2014-8986
Disclosure Date: November 24, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the selection list in the filters in the Configuration Report page (adm_config_report.php) in MantisBT 1.2.13 through 1.2.17 allows remote administrators to inject arbitrary web script or HTML via a crafted config option, a different vulnerability than CVE-2014-8987.
0