4.3
CVSSv2

CVE-2005-4522

Published: 28/12/2005 Updated: 08/03/2011
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in the view_filters_page.php filters script in Mantis 1.0.0rc3 and previous versions allow remote malicious users to inject arbitrary web script or HTML via the (1) view_type and (2) target_field parameters.

Vulnerable Product Search on Vulmon Subscribe to Product

mantis mantis 1.0.0 rc3

mantis mantis 1.0.0 rc1

mantis mantis 1.0.0 rc2

mantis mantis 1.0.0a3

mantis mantis 1.0.0a1

mantis mantis 1.0.0a2

Vendor Advisories

Several security related problems have been discovered in Mantis, a web-based bug tracking system The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2005-4238 Missing input sanitising allows remote attackers to inject arbitrary web script or HTML CVE-2005-4518 Tobias Klein discovered that Mantis a ...