Vulnerability index

Browse CVEs

28 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 9.0 CVE-2008-4687EPSS 67% manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort parameter containing PHP sequences… Mantis after 1.1.3 Fix from $1,9502008-10-22 HIGH 7.5 CVE-2008-4689 Mantis before 1.1.3 does not unset the session cookie during logout, which makes it easier for remote attackers to hijack sessions. Mantis after 1.1.2 Fix from $1,9502008-10-22 MEDIUM 5.0 CVE-2008-4688EPSS 12% core/string_api.php in Mantis before 1.1.3 does not check the privileges of the viewer before composing a link with issue data in the source anchor, … Mantis after 1.1.3 Fix from $1,6002008-10-22 HIGH 7.5 CVE-2008-3333 Directory traversal vulnerability in core/lang_api.php in Mantis before 1.1.2 allows remote attackers to include and execute arbitrary files via the … Mantis after 1.1.1 Fix from $1,9502008-07-27 MEDIUM 6.5 CVE-2008-3332EPSS 9% Eval injection vulnerability in adm_config_set.php in Mantis before 1.1.2 allows remote authenticated administrators to execute arbitrary code via th… Mantis after 1.1.1 Fix from $1,6002008-07-27 MEDIUM 5.0 CVE-2006-6574 Mantis before 1.1.0a2 does not implement per-item access control for Issue History (Bug History), which allows remote attackers to obtain sensitive i… Mantis after 1.1.0a1 Fix from $1,6002006-12-15 HIGH 10.0 CVE-2006-6515 Mantis before 1.1.0a2 sets the default value of $g_bug_reminder_threshold to "reporter" instead of a more privileged role, which has unknown impact a… Mantis after 1.1.0a1 Fix from $1,9502006-12-14 MEDIUM 6.8 CVE-2006-1577 Multiple cross-site scripting (XSS) vulnerabilities in view_all_set.php in Mantis 1.0.1, 1.0.0rc5, and earlier allow remote attackers to inject arbit… Mantis No fix yet Fix from $1,6002006-04-02 MEDIUM 5.0 CVE-2006-0840 manage_user_page.php in Mantis 1.00rc4 and earlier does not properly handle a sort parameter containing a ' (quote) character, which allows remote at… Mantis after 1.0.0_rc4 Fix from $1,6002006-02-22 HIGH 10.0 CVE-2006-0665 Unspecified vulnerability in (1) query_store.php and (2) manage_proj_create.php in Mantis before 1.0.0 has unknown impact and attack vectors. NOTE: … Mantis Patch available Fix from $1,9502006-02-13 HIGH 7.5 CVE-2005-4519 Multiple SQL injection vulnerabilities in the manage user page (manage_user_page.php) in Mantis 1.0.0rc3 and earlier allow remote attackers to execut… Mantis after 1.0.0_rc3 Fix from $1,9502005-12-28 MEDIUM 5.0 CVE-2005-4520 Unspecified "port injection" vulnerabilities in filters in Mantis 1.0.0rc3 and earlier have unknown impact and attack vectors. NOTE: due to a lack o… Mantis Patch available Fix from $1,6002005-12-28 MEDIUM 5.0 CVE-2005-4523 Mantis 1.0.0rc3 and earlier discloses private bugs via public RSS feeds, which allows remote attackers to obtain sensitive information. Mantis after 1.0.0_rc3 Fix from $1,6002005-12-28 HIGH 7.5 CVE-2005-3335EPSS 7% PHP file inclusion vulnerability in bug_sponsorship_list_view_inc.php in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbitrary PHP … Mantis Patch available Fix from $1,9502005-10-27 HIGH 7.5 CVE-2005-3336 SQL injection vulnerability in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbitrary SQL commands via unknown vectors. Mantis Patch available Fix from $1,9502005-10-27 HIGH 7.2 CVE-2005-3339 Mantis before 0.19.3 caches the User ID longer than necessary, which has unknown impact and attack vectors. Mantis Mitigation only Fix from $1,9502005-10-27 MEDIUM 5.0 CVE-2005-3338 Unspecified vulnerability in Mantis before 0.19.3, when using reminders, causes Mantis to display the real email addresses of users. Mantis Mitigation only Fix from $1,6002005-10-27 HIGH 7.5 CVE-2005-2556 core/database_api.php in Mantis 0.19.0a1 through 1.0.0a3, with register_globals enabled, allows remote attackers to connect to internal databases by … Mantis Patch available Fix from $1,9502005-08-24 HIGH 7.5 CVE-2004-1734 PHP remote file inclusion vulnerability in Mantis 0.19.0a allows remote attackers to execute arbitrary PHP code by modifying the (1) t_core_path para… Mantis Patch available Fix from $1,9502004-12-31 MEDIUM 5.0 CVE-2004-2666 Mantis before 20041016 provides a complete Issue History (Bug History) in the web interface regardless of view_history_threshold, which allows remote… Mantis Patch available Fix from $1,6002004-12-31 MEDIUM 5.0 CVE-2004-1731 signup_page.php in Mantis bugtracker allows remote attackers to send e-mail bombs by creating multiple users and providing the same e-mail address. Mantis Patch available Fix from $1,6002004-08-20 HIGH 10.0 CVE-2002-1110 Multiple SQL injection vulnerabilities in Mantis 0.17.2 and earlier, when running without magic_quotes_gpc enabled, allows remote attackers to gain p… Mantis Patch available Fix from $1,9502002-10-04 HIGH 7.5 CVE-2002-1113 summary_graph_functions.php in Mantis 0.17.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the g_jpgraph_path parame… Mantis Patch available Fix from $1,9502002-10-04 HIGH 7.5 CVE-2002-1114 config_inc2.php in Mantis before 0.17.4 allows remote attackers to execute arbitrary code or read arbitrary files via the parameters (1) g_bottom_inc… Mantis Patch available Fix from $1,9502002-10-04 HIGH 7.5 CVE-2002-1116 The "View Bugs" page (view_all_bug_page.php) in Mantis 0.17.4a and earlier includes summaries of private bugs for users that do not have access to an… Mantis Patch available Fix from $1,9502002-10-04 MEDIUM 5.0 CVE-2002-1111 print_all_bug_page.php in Mantis 0.17.3 and earlier does not verify the limit_reporters option, which allows remote attackers to view bug summaries f… Mantis Patch available Fix from $1,6002002-10-04 MEDIUM 5.0 CVE-2002-1112 Mantis before 0.17.4 allows remote attackers to list project bugs without authentication by modifying the cookie that is used by the "View Bugs" page. Mantis Patch available Fix from $1,6002002-10-04 MEDIUM 5.0 CVE-2002-1115 Mantis 0.17.4a and earlier allows remote attackers to view private bugs by modifying the f_id bug ID parameter to (1) bug_update_advanced_page.php, (… Mantis Patch available Fix from $1,6002002-10-04