Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mantis vulnerabilities and exploits
(subscribe to this query)
445
VMScore
CVE-2005-4521
CRLF injection vulnerability in Mantis 1.0.0rc3 and previous versions allows remote malicious users to modify HTTP headers and conduct HTTP response splitting attacks via (1) the return parameter in login_cookie_test.php and (2) ref parameter in login_select_proj_page.php.
445
VMScore
CVE-2005-4524
Mantis 1.0.0rc3 does not properly handle "Make note private" when a bug is being resolved, which has unknown impact and attack vectors, probably related to an information leak.
445
VMScore
CVE-2005-3338
Unspecified vulnerability in Mantis prior to 0.19.3, when using reminders, causes Mantis to display the real email addresses of users.
Mantis Mantis 0.19.0
Mantis Mantis 0.19.0 Rc1
Mantis Mantis 0.19.0a1
Mantis Mantis 0.19.1
Mantis Mantis 0.19.3
Mantis Mantis 0.19.0a2
Mantis Mantis 0.19.2
445
VMScore
CVE-2004-2666
Mantis prior to 20041016 provides a complete Issue History (Bug History) in the web interface regardless of view_history_threshold, which allows remote malicious users to obtain sensitive information (private bug details) by visiting a bug's web page.
Mantis Mantis 0.10
Mantis Mantis 0.10.1
Mantis Mantis 0.14.7
Mantis Mantis 0.14.8
Mantis Mantis 0.15
Mantis Mantis 0.15.1
Mantis Mantis 0.17
Mantis Mantis 0.17.1
Mantis Mantis 0.17.2
Mantis Mantis 0.17.3
Mantis Mantis 0.18a1
Mantis Mantis 0.19
Mantis Mantis 0.11
Mantis Mantis 0.12
Mantis Mantis 0.14.4
Mantis Mantis 0.14.6
Mantis Mantis 0.15.10
Mantis Mantis 0.15.12
Mantis Mantis 0.15.8
Mantis Mantis 0.16
Mantis Mantis 0.17.4a
Mantis Mantis 0.18
445
VMScore
CVE-2002-1115
Mantis 0.17.4a and previous versions allows remote malicious users to view private bugs by modifying the f_id bug ID parameter to (1) bug_update_advanced_page.php, (2) bug_update_page.php, (3) view_bug_advanced_page.php, or (4) view_bug_page.php.
Mantis Mantis 0.17.2
Mantis Mantis 0.17.3
Mantis Mantis 0.17.0
Mantis Mantis 0.17.1
Mantis Mantis 0.17.4
Mantis Mantis 0.17.4a
445
VMScore
CVE-2002-1111
print_all_bug_page.php in Mantis 0.17.3 and previous versions does not verify the limit_reporters option, which allows remote malicious users to view bug summaries for bugs that would otherwise be restricted.
Mantis Mantis 0.16.0
Mantis Mantis 0.16.1
Mantis Mantis 0.17.0
Mantis Mantis 0.17.1
Mantis Mantis 0.17.2
Mantis Mantis 0.17.3
445
VMScore
CVE-2002-1112
Mantis prior to 0.17.4 allows remote malicious users to list project bugs without authentication by modifying the cookie that is used by the "View Bugs" page.
Mantis Mantis 0.15.10
Mantis Mantis 0.15.8
Mantis Mantis 0.15.9
Mantis Mantis 0.15.6
Mantis Mantis 0.15.7
Mantis Mantis 0.17.2
Mantis Mantis 0.17.3
Mantis Mantis 0.15.3
Mantis Mantis 0.15.4
Mantis Mantis 0.15.5
Mantis Mantis 0.17.0
Mantis Mantis 0.17.1
Mantis Mantis 0.15.11
Mantis Mantis 0.15.12
Mantis Mantis 0.16.0
Mantis Mantis 0.16.1
440
VMScore
CVE-2006-0841
Multiple cross-site scripting (XSS) vulnerabilities in Mantis 1.00rc4 and previous versions allow remote malicious users to inject arbitrary web script or HTML via the (1) hide_status, (2) handler_id, (3) user_monitor, (4) reporter_id, (5) view_type, (6) show_severity, (7) show_c...
Mantis Mantis 0.11.1
Mantis Mantis 0.12
Mantis Mantis 0.14.1
Mantis Mantis 0.14.2
Mantis Mantis 0.15
Mantis Mantis 0.15.0
Mantis Mantis 0.15.1
Mantis Mantis 0.18
Mantis Mantis 0.18.0
Mantis Mantis 0.18.2
Mantis Mantis 0.18.3
Mantis Mantis 0.10
Mantis Mantis 0.10.0
Mantis Mantis 0.12.0
Mantis Mantis 0.13
Mantis Mantis 0.14.3
Mantis Mantis 0.14.4
Mantis Mantis 0.15.2
Mantis Mantis 0.16
Mantis Mantis 0.18.0 Rc1
Mantis Mantis 0.18.0a1
Mantis Mantis 0.18a1
2 EDB exploits
435
VMScore
CVE-2017-7620
MantisBT prior to 1.3.11, 2.x prior to 2.3.3, and 2.4.x prior to 2.4.1 omits a backslash check in string_api.php and consequently has conflicting interpretations of an initial \/ substring as introducing either a local pathname or a remote hostname, which leads to (1) arbitrary P...
Mantisbt Mantisbt 2.4.0
Mantisbt Mantisbt 2.0.1
Mantisbt Mantisbt 2.0.0
Mantisbt Mantisbt 2.1.0
Mantisbt Mantisbt
Mantisbt Mantisbt 2.1.1
Mantisbt Mantisbt 2.2.0
Mantisbt Mantisbt 2.1.2
Mantisbt Mantisbt 2.2.2
Mantisbt Mantisbt 2.2.3
Mantisbt Mantisbt 2.2.4
1 EDB exploit
435
VMScore
CVE-2011-2938
Multiple cross-site scripting (XSS) vulnerabilities in filter_api.php in MantisBT prior to 1.2.7 allow remote malicious users to inject arbitrary web script or HTML via a parameter, as demonstrated by the project_id parameter to search.php.
Mantisbt Mantisbt 1.1.1
Mantisbt Mantisbt 1.1.2
Mantisbt Mantisbt 1.1.8
Mantisbt Mantisbt 1.2.2
Mantisbt Mantisbt 1.2.4
Mantisbt Mantisbt 1.2.5
Mantisbt Mantisbt 1.0.3
Mantisbt Mantisbt 1.0.2
Mantisbt Mantisbt 1.0.8
Mantisbt Mantisbt 1.1.0
Mantisbt Mantisbt 1.0.6
Mantisbt Mantisbt 1.2.0
Mantisbt Mantisbt 1.1.6
Mantisbt Mantisbt
Mantisbt Mantisbt 0.19.4
Mantisbt Mantisbt 0.19.3
Mantisbt Mantisbt 1.0.5
Mantisbt Mantisbt 1.2.1
Mantisbt Mantisbt 1.1.5
Mantisbt Mantisbt 1.2.3
Mantisbt Mantisbt 1.0.1
Mantisbt Mantisbt 1.0.0
1 EDB exploit
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33572
CVE-2024-24919
CVE-2024-0230
CVE-2024-32714
HTML injection
local file inclusion
CVE-2024-31098
CVE-2024-31244
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »