Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mantis mantis 1.0.4 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2008-4689
Mantis prior to 1.1.3 does not unset the session cookie during logout, which makes it easier for remote malicious users to hijack sessions.
Mantis Mantis 1.0.6
Mantis Mantis 1.0.2
Mantis Mantis
Mantis Mantis 1.0.4
Mantis Mantis 1.0.8
Mantis Mantis 0.19.3
Mantis Mantis 1.0.7
Mantis Mantis 1.0.1
Mantis Mantis 1.0.3
Mantis Mantis 1.0.5
Mantis Mantis 1.1.1
Mantis Mantis 0.19.4
NA
CVE-2008-4687
manage_proj_page.php in Mantis prior to 1.1.4 allows remote authenticated users to execute arbitrary code via a sort parameter containing PHP sequences, which are processed by create_function within the multi_sort function in core/utility_api.php.
Mantis Mantis 1.0.6
Mantis Mantis 1.0.2
Mantis Mantis 1.0.4
Mantis Mantis 1.0.8
Mantis Mantis 0.19.3
Mantis Mantis 1.0.7
Mantis Mantis
Mantis Mantis 1.1.2
Mantis Mantis 1.0.1
Mantis Mantis 1.0.3
Mantis Mantis 1.0.5
Mantis Mantis 1.1.1
Mantis Mantis 0.19.4
2 EDB exploits
2 Github repositories
NA
CVE-2008-4688
core/string_api.php in Mantis prior to 1.1.3 does not check the privileges of the viewer before composing a link with issue data in the source anchor, which allows remote malicious users to discover an issue's title and status via a request with a modified issue number.
Mantis Mantis 1.0.6
Mantis Mantis 1.0.2
Mantis Mantis 1.0.4
Mantis Mantis 1.0.8
Mantis Mantis 0.19.3
Mantis Mantis 1.0.7
Mantis Mantis
Mantis Mantis 1.1.2
Mantis Mantis 1.0.1
Mantis Mantis 1.0.3
Mantis Mantis 1.0.5
Mantis Mantis 1.1.1
Mantis Mantis 0.19.4
NA
CVE-2006-6574
Mantis prior to 1.1.0a2 does not implement per-item access control for Issue History (Bug History), which allows remote malicious users to obtain sensitive information by reading the Change column, as demonstrated by the Change column of a custom field.
Mantis Mantis 1.0.6
Mantis Mantis 1.0.2
Mantis Mantis 1.0.4
Mantis Mantis 1.0.0 Rc3
Mantis Mantis 1.0.0 Rc1
Mantis Mantis 1.0.0 Rc2
Mantis Mantis 1.0.0
Mantis Mantis 1.0.1
Mantis Mantis 1.0.0 Rc4
Mantis Mantis 1.0.3
Mantis Mantis 1.0.5
Mantis Mantis 1.0.0a3
Mantis Mantis 1.0.0a1
Mantis Mantis 1.0.0a2
Mantis Mantis 1.0.0 Rc5
Mantis Mantis
NA
CVE-2006-6515
Mantis prior to 1.1.0a2 sets the default value of $g_bug_reminder_threshold to "reporter" instead of a more privileged role, which has unknown impact and attack vectors, possibly related to frequency of reminders.
Mantis Mantis 1.0.6
Mantis Mantis 1.0.2
Mantis Mantis 1.0.4
Mantis Mantis 1.0.0 Rc3
Mantis Mantis 1.0.0 Rc1
Mantis Mantis 1.0.0 Rc2
Mantis Mantis 1.0.0
Mantis Mantis 1.0.1
Mantis Mantis 1.0.0 Rc4
Mantis Mantis 1.0.3
Mantis Mantis 1.0.5
Mantis Mantis 1.0.0a3
Mantis Mantis 1.0.0a1
Mantis Mantis 1.0.0a2
Mantis Mantis 1.0.0 Rc5
Mantis Mantis
NA
CVE-2008-3331
Cross-site scripting (XSS) vulnerability in return_dynamic_filters.php in Mantis prior to 1.1.2 allows remote malicious users to inject arbitrary web script or HTML via the filter_target parameter.
Mantis Mantis 0.10.2
Mantis Mantis 0.10
Mantis Mantis 0.12.0
Mantis Mantis 0.14.7
Mantis Mantis 1.0.6
Mantis Mantis 0.19
Mantis Mantis 0.18.2
Mantis Mantis 0.18.0
Mantis Mantis 1.0.2
Mantis Mantis 0.15.12
Mantis Mantis 0.18.0a2
Mantis Mantis 0.18.0a4
Mantis Mantis 0.15.3
Mantis Mantis 0.18
Mantis Mantis 0.15.0
Mantis Mantis 1.0.4
Mantis Mantis 1.0.0 Rc3
Mantis Mantis 0.15.9
Mantis Mantis 0.14.2
Mantis Mantis 0.9.1
Mantis Mantis 0.13
Mantis Mantis 0.10.1
1 EDB exploit
NA
CVE-2008-3333
Directory traversal vulnerability in core/lang_api.php in Mantis prior to 1.1.2 allows remote malicious users to include and execute arbitrary files via the language parameter to the user preferences page (account_prefs_update.php).
Mantis Mantis 0.10.2
Mantis Mantis 0.10
Mantis Mantis 0.12.0
Mantis Mantis 0.14.7
Mantis Mantis 1.0.6
Mantis Mantis 0.19
Mantis Mantis 0.18.2
Mantis Mantis 0.18.0
Mantis Mantis 1.0.2
Mantis Mantis 0.15.12
Mantis Mantis 0.18.0a2
Mantis Mantis 0.18.0a4
Mantis Mantis 0.15.3
Mantis Mantis 0.18
Mantis Mantis 0.15.0
Mantis Mantis 1.0.4
Mantis Mantis 1.0.0 Rc3
Mantis Mantis 0.15.9
Mantis Mantis 0.14.2
Mantis Mantis 0.9.1
Mantis Mantis 0.13
Mantis Mantis 0.10.1
NA
CVE-2008-3332
Eval injection vulnerability in adm_config_set.php in Mantis prior to 1.1.2 allows remote authenticated administrators to execute arbitrary code via the value parameter.
Mantis Mantis 0.10.2
Mantis Mantis 0.10
Mantis Mantis 0.12.0
Mantis Mantis 0.14.7
Mantis Mantis 1.0.6
Mantis Mantis 0.19
Mantis Mantis 0.18.2
Mantis Mantis 0.18.0
Mantis Mantis 1.0.2
Mantis Mantis 0.15.12
Mantis Mantis 0.18.0a2
Mantis Mantis 0.18.0a4
Mantis Mantis 0.15.3
Mantis Mantis 0.18
Mantis Mantis 0.15.0
Mantis Mantis 1.0.4
Mantis Mantis 1.0.0 Rc3
Mantis Mantis 0.15.9
Mantis Mantis 0.14.2
Mantis Mantis 0.9.1
Mantis Mantis 0.13
Mantis Mantis 0.10.1
1 EDB exploit
NA
CVE-2011-3357
Directory traversal vulnerability in bug_actiongroup_ext_page.php in MantisBT prior to 1.2.8 allows remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the action parameter, related to bug_actiongroup_page.php.
Mantisbt Mantisbt 0.19.4
Mantisbt Mantisbt 1.0.2
Mantisbt Mantisbt 1.2.2
Mantisbt Mantisbt 1.2.5
Mantisbt Mantisbt 0.19.3
Mantisbt Mantisbt 1.1.6
Mantisbt Mantisbt 1.2.0
Mantisbt Mantisbt 1.1.4
Mantisbt Mantisbt 1.0.3
Mantisbt Mantisbt 1.1.0
Mantisbt Mantisbt 1.1.5
Mantisbt Mantisbt 1.0.7
Mantisbt Mantisbt 1.2.3
Mantisbt Mantisbt 1.1.2
Mantisbt Mantisbt 1.0.1
Mantisbt Mantisbt 1.2.6
Mantisbt Mantisbt 1.0.0
Mantisbt Mantisbt
Mantisbt Mantisbt 1.2.1
Mantisbt Mantisbt 1.0.4
Mantisbt Mantisbt 1.1.7
Mantisbt Mantisbt 1.0.5
NA
CVE-2011-3358
Multiple cross-site scripting (XSS) vulnerabilities in MantisBT prior to 1.2.8 allow remote malicious users to inject arbitrary web script or HTML via the (1) os, (2) os_build, or (3) platform parameter to (a) bug_report_page.php or (b) bug_update_advanced_page.php, related to us...
Mantisbt Mantisbt 0.19.4
Mantisbt Mantisbt 1.0.2
Mantisbt Mantisbt 1.2.2
Mantisbt Mantisbt 1.2.5
Mantisbt Mantisbt 0.19.3
Mantisbt Mantisbt 1.1.6
Mantisbt Mantisbt 1.2.0
Mantisbt Mantisbt 1.1.4
Mantisbt Mantisbt 1.0.3
Mantisbt Mantisbt 1.1.0
Mantisbt Mantisbt 1.1.5
Mantisbt Mantisbt 1.0.7
Mantisbt Mantisbt 1.2.3
Mantisbt Mantisbt 1.1.2
Mantisbt Mantisbt 1.0.1
Mantisbt Mantisbt 1.2.6
Mantisbt Mantisbt 1.0.0
Mantisbt Mantisbt
Mantisbt Mantisbt 1.2.1
Mantisbt Mantisbt 1.0.4
Mantisbt Mantisbt 1.1.7
Mantisbt Mantisbt 1.0.5
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
type confusion
IMAP
CVE-2024-36103
CVE-2024-28995
CVE-2024-37325
CVE-2024-30078
CVE-2024-30082
SQL injection
CVE-2024-30052
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »