Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mantisbt mantisbt vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2017-7620
MantisBT prior to 1.3.11, 2.x prior to 2.3.3, and 2.4.x prior to 2.4.1 omits a backslash check in string_api.php and consequently has conflicting interpretations of an initial \/ substring as introducing either a local pathname or a remote hostname, which leads to (1) arbitrary P...
Mantisbt Mantisbt 2.1.0
Mantisbt Mantisbt 2.1.2
Mantisbt Mantisbt
Mantisbt Mantisbt 2.1.1
Mantisbt Mantisbt 2.2.2
Mantisbt Mantisbt 2.0.1
Mantisbt Mantisbt 2.4.0
Mantisbt Mantisbt 2.2.4
Mantisbt Mantisbt 2.2.3
Mantisbt Mantisbt 2.0.0
Mantisbt Mantisbt 2.2.0
1 EDB exploit
4.3
CVSSv2
CVE-2017-7897
A cross-site scripting (XSS) vulnerability in the MantisBT (2.3.x prior to 2.3.2) Timeline include page, used in My View (my_view_page.php) and User Information (view_user_page.php) pages, allows remote malicious users to inject arbitrary code (if CSP settings permit it) through ...
Mantisbt Mantisbt 2.3.0
Mantisbt Mantisbt 2.3.1
6.5
CVSSv2
CVE-2017-7615
MantisBT up to and including 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php.
Mantisbt Mantisbt
1 EDB exploit
3.5
CVSSv2
CVE-2017-7241
A cross-site scripting (XSS) vulnerability in the MantisBT Move Attachments page (move_attachments_page.php, part of admin tools) allows remote malicious users to inject arbitrary code through a crafted 'type' parameter, if Content Security Protection (CSP) settings all...
Mantisbt Mantisbt 2.3.0
Mantisbt Mantisbt 2.1.0
Mantisbt Mantisbt 2.0.0
Mantisbt Mantisbt 2.1.2
Mantisbt Mantisbt 1.3.4
Mantisbt Mantisbt 2.1.3
Mantisbt Mantisbt 1.3.0
Mantisbt Mantisbt 1.2.18
Mantisbt Mantisbt 2.1.1
Mantisbt Mantisbt 2.2.2
Mantisbt Mantisbt 2.2.1
Mantisbt Mantisbt 1.3.7
Mantisbt Mantisbt 1.2.19
Mantisbt Mantisbt 1.3.3
Mantisbt Mantisbt 2.0.1
Mantisbt Mantisbt 1.3.8
Mantisbt Mantisbt 1.3.9
Mantisbt Mantisbt 1.2.16
Mantisbt Mantisbt 1.3.2
Mantisbt Mantisbt 1.3.5
Mantisbt Mantisbt 2.2.3
Mantisbt Mantisbt 1.2.17
3.5
CVSSv2
CVE-2017-6973
A cross-site scripting (XSS) vulnerability in the MantisBT Configuration Report page (adm_config_report.php) allows remote malicious users to inject arbitrary code through a crafted 'action' parameter. This is fixed in 1.3.8, 2.1.2, and 2.2.2.
Mantisbt Mantisbt 2.1.0
Mantisbt Mantisbt 2.0.0
Mantisbt Mantisbt 2.1.2
Mantisbt Mantisbt 1.3.4
Mantisbt Mantisbt 2.1.3
Mantisbt Mantisbt 1.3.0
Mantisbt Mantisbt 2.1.1
Mantisbt Mantisbt 2.2.1
Mantisbt Mantisbt 1.3.7
Mantisbt Mantisbt 1.3.3
Mantisbt Mantisbt 2.0.1
Mantisbt Mantisbt 1.3.8
Mantisbt Mantisbt 1.3.9
Mantisbt Mantisbt 1.3.2
Mantisbt Mantisbt 1.3.5
Mantisbt Mantisbt 1.3.6
Mantisbt Mantisbt 1.3.1
Mantisbt Mantisbt 2.2.0
3.5
CVSSv2
CVE-2017-7309
A cross-site scripting (XSS) vulnerability in the MantisBT Configuration Report page (adm_config_report.php) allows remote malicious users to inject arbitrary code (if CSP settings permit it) through a crafted 'config_option' parameter. This is fixed in 1.3.9, 2.1.3, an...
Mantisbt Mantisbt 2.1.0
Mantisbt Mantisbt 2.0.0
Mantisbt Mantisbt 2.1.2
Mantisbt Mantisbt 1.3.4
Mantisbt Mantisbt 2.1.3
Mantisbt Mantisbt 1.3.0
Mantisbt Mantisbt 2.1.1
Mantisbt Mantisbt 2.2.2
Mantisbt Mantisbt 2.2.1
Mantisbt Mantisbt 1.3.7
Mantisbt Mantisbt 1.3.3
Mantisbt Mantisbt 2.0.1
Mantisbt Mantisbt 1.3.8
Mantisbt Mantisbt 1.3.9
Mantisbt Mantisbt 1.3.2
Mantisbt Mantisbt 1.3.5
Mantisbt Mantisbt 1.3.6
Mantisbt Mantisbt 1.3.1
Mantisbt Mantisbt 2.2.0
4.3
CVSSv2
CVE-2017-7222
A cross-site scripting (XSS) vulnerability in MantisBT prior to 2.1.1 allows remote malicious users to inject arbitrary HTML or JavaScript (if MantisBT's CSP settings permit it) by modifying 'window_title' in the application configuration. This requires privileged ...
Mantisbt Mantisbt
4.3
CVSSv2
CVE-2017-6958
An XSS vulnerability in the MantisBT Source Integration Plugin (prior to 2.0.2) search result page allows an malicious user to inject arbitrary HTML or JavaScript (if MantisBT's CSP settings permit it) by crafting any valid parameter.
Mantisbt Source Integration
4.3
CVSSv2
CVE-2017-6799
A cross-site scripting (XSS) vulnerability in view_filters_page.php in MantisBT prior to 2.2.1 allows remote malicious users to inject arbitrary JavaScript via the 'view_type' parameter.
Mantisbt Mantisbt
1 Github repository
4.3
CVSSv2
CVE-2017-6797
A cross-site scripting (XSS) vulnerability in bug_change_status_page.php in MantisBT prior to 1.3.7 and 2.x prior to 2.2.1 allows remote malicious users to inject arbitrary JavaScript via the 'action_type' parameter.
Mantisbt Mantisbt
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-23692
malicious code
XML injection
CVE-2024-28020
CVE-2024-35252
CVE-2024-5833
CVE-2024-30066
injection
CVE-2024-23282
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »