Vulnerability index

Browse CVEs

28 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mantis HIGH 9.0
CVE-2008-4687EPSS 67%

manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort parameter containing PHP sequences…

Fix: after 1.1.3
Fix from $1,950 2008-10-22
Mantis HIGH 7.5
CVE-2008-4689

Mantis before 1.1.3 does not unset the session cookie during logout, which makes it easier for remote attackers to hijack sessions.

Fix: after 1.1.2
Fix from $1,950 2008-10-22
Mantis MEDIUM 5.0
CVE-2008-4688EPSS 12%

core/string_api.php in Mantis before 1.1.3 does not check the privileges of the viewer before composing a link with issue data in the source anchor, …

Fix: after 1.1.3
Fix from $1,600 2008-10-22
Mantis HIGH 7.5
CVE-2008-3333

Directory traversal vulnerability in core/lang_api.php in Mantis before 1.1.2 allows remote attackers to include and execute arbitrary files via the …

Fix: after 1.1.1
Fix from $1,950 2008-07-27
Mantis MEDIUM 6.5
CVE-2008-3332EPSS 9%

Eval injection vulnerability in adm_config_set.php in Mantis before 1.1.2 allows remote authenticated administrators to execute arbitrary code via th…

Fix: after 1.1.1
Fix from $1,600 2008-07-27
Mantis MEDIUM 5.0
CVE-2006-6574

Mantis before 1.1.0a2 does not implement per-item access control for Issue History (Bug History), which allows remote attackers to obtain sensitive i…

Fix: after 1.1.0a1
Fix from $1,600 2006-12-15
Mantis HIGH 10.0
CVE-2006-6515

Mantis before 1.1.0a2 sets the default value of $g_bug_reminder_threshold to "reporter" instead of a more privileged role, which has unknown impact a…

Fix: after 1.1.0a1
Fix from $1,950 2006-12-14
Mantis MEDIUM 6.8
CVE-2006-1577

Multiple cross-site scripting (XSS) vulnerabilities in view_all_set.php in Mantis 1.0.1, 1.0.0rc5, and earlier allow remote attackers to inject arbit…

No fix yet
Fix from $1,600 2006-04-02
Mantis MEDIUM 5.0
CVE-2006-0840

manage_user_page.php in Mantis 1.00rc4 and earlier does not properly handle a sort parameter containing a ' (quote) character, which allows remote at…

Fix: after 1.0.0_rc4
Fix from $1,600 2006-02-22
Mantis HIGH 10.0
CVE-2006-0665

Unspecified vulnerability in (1) query_store.php and (2) manage_proj_create.php in Mantis before 1.0.0 has unknown impact and attack vectors. NOTE: …

Patch available
Fix from $1,950 2006-02-13
Mantis HIGH 7.5
CVE-2005-4519

Multiple SQL injection vulnerabilities in the manage user page (manage_user_page.php) in Mantis 1.0.0rc3 and earlier allow remote attackers to execut…

Fix: after 1.0.0_rc3
Fix from $1,950 2005-12-28
Mantis MEDIUM 5.0
CVE-2005-4520

Unspecified "port injection" vulnerabilities in filters in Mantis 1.0.0rc3 and earlier have unknown impact and attack vectors. NOTE: due to a lack o…

Patch available
Fix from $1,600 2005-12-28
Mantis MEDIUM 5.0
CVE-2005-4523

Mantis 1.0.0rc3 and earlier discloses private bugs via public RSS feeds, which allows remote attackers to obtain sensitive information.

Fix: after 1.0.0_rc3
Fix from $1,600 2005-12-28
Mantis HIGH 7.5
CVE-2005-3335EPSS 7%

PHP file inclusion vulnerability in bug_sponsorship_list_view_inc.php in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbitrary PHP …

Patch available
Fix from $1,950 2005-10-27
Mantis HIGH 7.5
CVE-2005-3336

SQL injection vulnerability in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

Patch available
Fix from $1,950 2005-10-27
Mantis HIGH 7.2
CVE-2005-3339

Mantis before 0.19.3 caches the User ID longer than necessary, which has unknown impact and attack vectors.

Mitigation only
Fix from $1,950 2005-10-27
Mantis MEDIUM 5.0
CVE-2005-3338

Unspecified vulnerability in Mantis before 0.19.3, when using reminders, causes Mantis to display the real email addresses of users.

Mitigation only
Fix from $1,600 2005-10-27
Mantis HIGH 7.5
CVE-2005-2556

core/database_api.php in Mantis 0.19.0a1 through 1.0.0a3, with register_globals enabled, allows remote attackers to connect to internal databases by …

Patch available
Fix from $1,950 2005-08-24
Mantis HIGH 7.5
CVE-2004-1734

PHP remote file inclusion vulnerability in Mantis 0.19.0a allows remote attackers to execute arbitrary PHP code by modifying the (1) t_core_path para…

Patch available
Fix from $1,950 2004-12-31
Mantis MEDIUM 5.0
CVE-2004-2666

Mantis before 20041016 provides a complete Issue History (Bug History) in the web interface regardless of view_history_threshold, which allows remote…

Patch available
Fix from $1,600 2004-12-31
Mantis MEDIUM 5.0
CVE-2004-1731

signup_page.php in Mantis bugtracker allows remote attackers to send e-mail bombs by creating multiple users and providing the same e-mail address.

Patch available
Fix from $1,600 2004-08-20
Mantis HIGH 10.0
CVE-2002-1110

Multiple SQL injection vulnerabilities in Mantis 0.17.2 and earlier, when running without magic_quotes_gpc enabled, allows remote attackers to gain p…

Patch available
Fix from $1,950 2002-10-04
Mantis HIGH 7.5
CVE-2002-1113

summary_graph_functions.php in Mantis 0.17.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the g_jpgraph_path parame…

Patch available
Fix from $1,950 2002-10-04
Mantis HIGH 7.5
CVE-2002-1114

config_inc2.php in Mantis before 0.17.4 allows remote attackers to execute arbitrary code or read arbitrary files via the parameters (1) g_bottom_inc…

Patch available
Fix from $1,950 2002-10-04
Mantis HIGH 7.5
CVE-2002-1116

The "View Bugs" page (view_all_bug_page.php) in Mantis 0.17.4a and earlier includes summaries of private bugs for users that do not have access to an…

Patch available
Fix from $1,950 2002-10-04
Mantis MEDIUM 5.0
CVE-2002-1111

print_all_bug_page.php in Mantis 0.17.3 and earlier does not verify the limit_reporters option, which allows remote attackers to view bug summaries f…

Patch available
Fix from $1,600 2002-10-04
Mantis MEDIUM 5.0
CVE-2002-1112

Mantis before 0.17.4 allows remote attackers to list project bugs without authentication by modifying the cookie that is used by the "View Bugs" page.

Patch available
Fix from $1,600 2002-10-04
Mantis MEDIUM 5.0
CVE-2002-1115

Mantis 0.17.4a and earlier allows remote attackers to view private bugs by modifying the f_id bug ID parameter to (1) bug_update_advanced_page.php, (…

Patch available
Fix from $1,600 2002-10-04