3.5
CVSSv2

CVE-2010-3303

Published: 05/10/2010 Updated: 27/08/2013
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in MantisBT prior to 1.2.3 allow remote authenticated administrators to inject arbitrary web script or HTML via (1) a plugin name, related to manage_plugin_uninstall.php; (2) an enumeration value or (3) a String value of a custom field, related to core/cfdefs/cfdef_standard.php; or a (4) project or (5) category name to print_all_bug_page_word.php.

Vulnerable Product Search on Vulmon Subscribe to Product

mantisbt mantisbt 1.1.7

mantisbt mantisbt 1.1.4

mantisbt mantisbt 1.1.1

mantisbt mantisbt 1.1.2

mantisbt mantisbt 1.1.0

mantisbt mantisbt 1.0.6

mantisbt mantisbt 0.19.3

mantisbt mantisbt 0.19.4

mantisbt mantisbt 0.19.2

mantisbt mantisbt 1.0.0a1

mantisbt mantisbt 1.0.0

mantisbt mantisbt 0.19.5

mantisbt mantisbt 1.1.6

mantisbt mantisbt 1.0.3

mantisbt mantisbt 1.0.2

mantisbt mantisbt 0.19.0a2

mantisbt mantisbt 0.19.0

mantisbt mantisbt 1.1.8

mantisbt mantisbt 1.2.0

mantisbt mantisbt 1.0.7

mantisbt mantisbt 1.0.4

mantisbt mantisbt 1.0.5

mantisbt mantisbt 0.18.0

mantisbt mantisbt 0.19.0a1

mantisbt mantisbt 1.0.0a2

mantisbt mantisbt 1.0.0a3

mantisbt mantisbt 1.2.1

mantisbt mantisbt

mantisbt mantisbt 1.1.5

mantisbt mantisbt 1.0.8

mantisbt mantisbt 1.0.1

mantisbt mantisbt 0.19.1