Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 9.0
CVE-2008-4687EPSS 67%
manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort parameter containing PHP sequences…
Mantis
after 1.1.3
HIGH 7.5
CVE-2008-4689
Mantis before 1.1.3 does not unset the session cookie during logout, which makes it easier for remote attackers to hijack sessions.
Mantis
after 1.1.2
MEDIUM 5.0
CVE-2008-4688EPSS 12%
core/string_api.php in Mantis before 1.1.3 does not check the privileges of the viewer before composing a link with issue data in the source anchor, …
Mantis
after 1.1.3
HIGH 7.5
CVE-2008-3333
Directory traversal vulnerability in core/lang_api.php in Mantis before 1.1.2 allows remote attackers to include and execute arbitrary files via the …
Mantis
after 1.1.1
MEDIUM 6.5
CVE-2008-3332EPSS 9%
Eval injection vulnerability in adm_config_set.php in Mantis before 1.1.2 allows remote authenticated administrators to execute arbitrary code via th…
Mantis
after 1.1.1
MEDIUM 5.0
CVE-2006-6574
Mantis before 1.1.0a2 does not implement per-item access control for Issue History (Bug History), which allows remote attackers to obtain sensitive i…
Mantis
after 1.1.0a1
HIGH 10.0
CVE-2006-6515
Mantis before 1.1.0a2 sets the default value of $g_bug_reminder_threshold to "reporter" instead of a more privileged role, which has unknown impact a…
Mantis
after 1.1.0a1
MEDIUM 6.8
CVE-2006-1577
Multiple cross-site scripting (XSS) vulnerabilities in view_all_set.php in Mantis 1.0.1, 1.0.0rc5, and earlier allow remote attackers to inject arbit…
Mantis
No fix yet
MEDIUM 5.0
CVE-2006-0840
manage_user_page.php in Mantis 1.00rc4 and earlier does not properly handle a sort parameter containing a ' (quote) character, which allows remote at…
Mantis
after 1.0.0_rc4
HIGH 10.0
CVE-2006-0665
Unspecified vulnerability in (1) query_store.php and (2) manage_proj_create.php in Mantis before 1.0.0 has unknown impact and attack vectors. NOTE: …
Mantis
Patch available
HIGH 7.5
CVE-2005-4519
Multiple SQL injection vulnerabilities in the manage user page (manage_user_page.php) in Mantis 1.0.0rc3 and earlier allow remote attackers to execut…
Mantis
after 1.0.0_rc3
MEDIUM 5.0
CVE-2005-4520
Unspecified "port injection" vulnerabilities in filters in Mantis 1.0.0rc3 and earlier have unknown impact and attack vectors. NOTE: due to a lack o…
Mantis
Patch available
MEDIUM 5.0
CVE-2005-4523
Mantis 1.0.0rc3 and earlier discloses private bugs via public RSS feeds, which allows remote attackers to obtain sensitive information.
Mantis
after 1.0.0_rc3
HIGH 7.5
CVE-2005-3335EPSS 7%
PHP file inclusion vulnerability in bug_sponsorship_list_view_inc.php in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbitrary PHP …
Mantis
Patch available
HIGH 7.5
CVE-2005-3336
SQL injection vulnerability in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
Mantis
Patch available
HIGH 7.2
CVE-2005-3339
Mantis before 0.19.3 caches the User ID longer than necessary, which has unknown impact and attack vectors.
Mantis
Mitigation only
MEDIUM 5.0
CVE-2005-3338
Unspecified vulnerability in Mantis before 0.19.3, when using reminders, causes Mantis to display the real email addresses of users.
Mantis
Mitigation only
HIGH 7.5
CVE-2005-2556
core/database_api.php in Mantis 0.19.0a1 through 1.0.0a3, with register_globals enabled, allows remote attackers to connect to internal databases by …
Mantis
Patch available
HIGH 7.5
CVE-2004-1734
PHP remote file inclusion vulnerability in Mantis 0.19.0a allows remote attackers to execute arbitrary PHP code by modifying the (1) t_core_path para…
Mantis
Patch available
MEDIUM 5.0
CVE-2004-2666
Mantis before 20041016 provides a complete Issue History (Bug History) in the web interface regardless of view_history_threshold, which allows remote…
Mantis
Patch available
MEDIUM 5.0
CVE-2004-1731
signup_page.php in Mantis bugtracker allows remote attackers to send e-mail bombs by creating multiple users and providing the same e-mail address.
Mantis
Patch available
HIGH 10.0
CVE-2002-1110
Multiple SQL injection vulnerabilities in Mantis 0.17.2 and earlier, when running without magic_quotes_gpc enabled, allows remote attackers to gain p…
Mantis
Patch available
HIGH 7.5
CVE-2002-1113
summary_graph_functions.php in Mantis 0.17.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the g_jpgraph_path parame…
Mantis
Patch available
HIGH 7.5
CVE-2002-1114
config_inc2.php in Mantis before 0.17.4 allows remote attackers to execute arbitrary code or read arbitrary files via the parameters (1) g_bottom_inc…
Mantis
Patch available
HIGH 7.5
CVE-2002-1116
The "View Bugs" page (view_all_bug_page.php) in Mantis 0.17.4a and earlier includes summaries of private bugs for users that do not have access to an…
Mantis
Patch available
MEDIUM 5.0
CVE-2002-1111
print_all_bug_page.php in Mantis 0.17.3 and earlier does not verify the limit_reporters option, which allows remote attackers to view bug summaries f…
Mantis
Patch available
MEDIUM 5.0
CVE-2002-1112
Mantis before 0.17.4 allows remote attackers to list project bugs without authentication by modifying the cookie that is used by the "View Bugs" page.
Mantis
Patch available
MEDIUM 5.0
CVE-2002-1115
Mantis 0.17.4a and earlier allows remote attackers to view private bugs by modifying the f_id bug ID parameter to (1) bug_update_advanced_page.php, (…
Mantis
Patch available