Mantis / Mantis
44 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2013-1811 | An access control issue in MantisBT before 1.2.13 allows users with "Reporter" permissions to change any issue to "New". | MEDIUM | 4.3 | Nov 7, 2019 |
| CVE-2008-4689 | mantis: logout without unsetting session cookie | HIGH | 7.5 | Oct 22, 2008 |
| CVE-2008-4688 | mantis: bug title and status leak to unauthorized users | MEDIUM | 5.0 | Oct 22, 2008 |
| CVE-2008-4687 | mantis: code execution by registered users via sort parameter to manage_proj_page.php | HIGH | 9.0 | Oct 22, 2008 |
| CVE-2008-3333 | mantis: arbitrary file inclusion through user preferences page | HIGH | 7.5 | Jul 27, 2008 |
| CVE-2008-3332 | mantis: code execution by users with administrative privileges | MEDIUM | 6.5 | Jul 27, 2008 |
| CVE-2008-3331 | mantis: XSS in return_dynamic_filters.php | LOW | 3.5 | Jul 27, 2008 |
| CVE-2008-0404 | mantis: XSS via "Most Active" on "Summary" screen | MEDIUM | 4.3 | Jan 23, 2008 |
| CVE-2007-6611 | Mantis 1.1.0 fixes a cross-site scripting flaw | MEDIUM | 4.3 | Jan 3, 2008 |
| CVE-2006-6574 | Mantis before 1.1.0a2 does not implement per-item access control for Issue History (Bug History), which allows remote attackers to obtain sensitive information… | MEDIUM | 5.0 | Dec 15, 2006 |
| CVE-2004-2666 | Mantis before 20041016 provides a complete Issue History (Bug History) in the web interface regardless of view_history_threshold, which allows remote attackers… | MEDIUM | 5.0 | Dec 15, 2006 |
| CVE-2006-6515 | Mantis before 1.1.0a2 sets the default value of $g_bug_reminder_threshold to "reporter" instead of a more privileged role, which has unknown impact and attack… | HIGH | 10.0 | Dec 14, 2006 |
| CVE-2006-1577 | Multiple cross-site scripting (XSS) vulnerabilities in view_all_set.php in Mantis 1.0.1, 1.0.0rc5, and earlier allow remote attackers to inject arbitrary web s… | MEDIUM | 6.8 | Apr 2, 2006 |
| CVE-2006-0841 | Multiple cross-site scripting (XSS) vulnerabilities in Mantis 1.00rc4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) hid… | MEDIUM | 4.3 | Feb 22, 2006 |
| CVE-2006-0840 | manage_user_page.php in Mantis 1.00rc4 and earlier does not properly handle a sort parameter containing a ' (quote) character, which allows remote attackers to… | MEDIUM | 5.0 | Feb 22, 2006 |
| CVE-2006-0665 | Unspecified vulnerability in (1) query_store.php and (2) manage_proj_create.php in Mantis before 1.0.0 has unknown impact and attack vectors. NOTE: the provena… | HIGH | 10.0 | Feb 13, 2006 |
| CVE-2006-0664 | Cross-site scripting (XSS) vulnerability in config_defaults_inc.php in Mantis before 1.0 allows remote attackers to inject arbitrary web script or HTML via unk… | MEDIUM | 4.3 | Feb 13, 2006 |
| CVE-2006-0147 | Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) Post… | HIGH | 7.5 | Jan 9, 2006 |
| CVE-2006-0146 | The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6… | HIGH | 7.5 | Jan 9, 2006 |
| CVE-2005-4523 | Mantis 1.0.0rc3 and earlier discloses private bugs via public RSS feeds, which allows remote attackers to obtain sensitive information. | MEDIUM | 5.0 | Dec 28, 2005 |
| CVE-2005-4522 | Multiple cross-site scripting (XSS) vulnerabilities in the view_filters_page.php filters script in Mantis 1.0.0rc3 and earlier allow remote attackers to inject… | MEDIUM | 4.3 | Dec 28, 2005 |
| CVE-2005-4520 | Unspecified "port injection" vulnerabilities in filters in Mantis 1.0.0rc3 and earlier have unknown impact and attack vectors. NOTE: due to a lack of relevant… | MEDIUM | 5.0 | Dec 28, 2005 |
| CVE-2005-4519 | Multiple SQL injection vulnerabilities in the manage user page (manage_user_page.php) in Mantis 1.0.0rc3 and earlier allow remote attackers to execute arbitrar… | HIGH | 7.5 | Dec 28, 2005 |
| CVE-2005-4238 | Cross-site scripting (XSS) vulnerability in view_filters_page.php in Mantis 1.0.0rc3 and earlier allows remote attackers to inject arbitrary web script or HTML… | MEDIUM | 4.3 | Dec 14, 2005 |
| CVE-2005-3339 | Mantis before 0.19.3 caches the User ID longer than necessary, which has unknown impact and attack vectors. | HIGH | 7.2 | Oct 27, 2005 |
Showing 1 to 25 of 44 CVEs