Skip to content
Noroxi

mantis records

46 published records for vendor mantis.

All records

46 records
  • manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort parameter containing PHP

    CriticalCVSS 9.0WeaponizedEPSS 67%

    mantis · mantisOct 22, 2008

  • Multiple SQL injection vulnerabilities in Mantis 0.17.2 and earlier, when running without magic_quotes_gpc enabled, allows remote attackers

    CriticalCVSS 10.0No exploitEPSS 2%

    mantis · mantisOct 4, 2002

  • Unspecified vulnerability in (1) query_store.php and (2) manage_proj_create.php in Mantis before 1.0.0 has unknown impact and attack vectors

    CriticalCVSS 10.0No exploitEPSS 2%

    mantis · mantisFeb 13, 2006

  • Mantis before 1.1.0a2 sets the default value of $g_bug_reminder_threshold to "reporter" instead of a more privileged role, which has unknown

    CriticalCVSS 10.0No exploitEPSS 1%

    mantis · mantisDec 13, 2006

  • CVE-2006-0146
    34Monitor

    The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Ca

    HighCVSS 7.5Proof of conceptEPSS 13%

    mantis · mantisJan 9, 2006

  • CVE-2006-0147
    34Monitor

    Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (

    HighCVSS 7.5Proof of conceptEPSS 13%

    john lim · adodbJan 9, 2006

  • CVE-2005-3335
    32Monitor

    PHP file inclusion vulnerability in bug_sponsorship_list_view_inc.php in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbit

    HighCVSS 7.5No exploitEPSS 7%

    mantis · mantisOct 27, 2005

  • CVE-2005-4518
    31Monitor

    Mantis before 0.19.4 allows remote attackers to bypass the file upload size restriction by modifying the max_file_size parameter to (1) bug_

    HighCVSS 7.5No exploitEPSS 4%

    mantis · mantisDec 27, 2005

  • CVE-2002-1113
    31Monitor

    summary_graph_functions.php in Mantis 0.17.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the g_jpgraph_pa

    HighCVSS 7.5Proof of conceptEPSS 3%

    mantis · mantisOct 4, 2002

  • CVE-2002-1114
    31Monitor

    config_inc2.php in Mantis before 0.17.4 allows remote attackers to execute arbitrary code or read arbitrary files via the parameters (1) g_b

    HighCVSS 7.5No exploitEPSS 3%

    mantis · mantisOct 4, 2002

  • CVE-2008-4689
    31Monitor

    Mantis before 1.1.3 does not unset the session cookie during logout, which makes it easier for remote attackers to hijack sessions.

    HighCVSS 7.5No exploitEPSS 2%

    mantis · mantisOct 22, 2008

  • CVE-2008-3333
    31Monitor

    Directory traversal vulnerability in core/lang_api.php in Mantis before 1.1.2 allows remote attackers to include and execute arbitrary files

    HighCVSS 7.5No exploitEPSS 2%

    mantis · mantisJul 27, 2008

  • CVE-2005-4519
    31Monitor

    Multiple SQL injection vulnerabilities in the manage user page (manage_user_page.php) in Mantis 1.0.0rc3 and earlier allow remote attackers

    HighCVSS 7.5No exploitEPSS 2%

    mantis · mantisDec 27, 2005

  • CVE-2005-3336
    31Monitor

    SQL injection vulnerability in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

    HighCVSS 7.5No exploitEPSS 2%

    mantis · mantisOct 27, 2005

  • CVE-2004-1734
    31Monitor

    PHP remote file inclusion vulnerability in Mantis 0.19.0a allows remote attackers to execute arbitrary PHP code by modifying the (1) t_core_

    HighCVSS 7.5No exploitEPSS 2%

    mantis · mantisDec 31, 2004

  • CVE-2005-2556
    30Monitor

    core/database_api.php in Mantis 0.19.0a1 through 1.0.0a3, with register_globals enabled, allows remote attackers to connect to internal data

    HighCVSS 7.5No exploitEPSS 2%

    mantis · mantisAug 24, 2005

  • CVE-2002-1116
    30Monitor

    The "View Bugs" page (view_all_bug_page.php) in Mantis 0.17.4a and earlier includes summaries of private bugs for users that do not have acc

    HighCVSS 7.5No exploitEPSS 1%

    mantis · mantisOct 4, 2002

  • CVE-2008-3332
    29Monitor

    Eval injection vulnerability in adm_config_set.php in Mantis before 1.1.2 allows remote authenticated administrators to execute arbitrary co

    MediumCVSS 6.5Proof of conceptEPSS 9%

    mantis · mantisJul 27, 2008

  • CVE-2006-1577
    28Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in view_all_set.php in Mantis 1.0.1, 1.0.0rc5, and earlier allow remote attackers to inj

    MediumCVSS 6.8No exploitEPSS 2%

    mantis · mantisApr 2, 2006

  • CVE-2005-3339
    28Monitor

    Mantis before 0.19.3 caches the User ID longer than necessary, which has unknown impact and attack vectors.

    HighCVSS 7.2No exploitEPSS 0%

    mantis · mantisOct 27, 2005

  • CVE-2008-4688
    24Monitor

    core/string_api.php in Mantis before 1.1.3 does not check the privileges of the viewer before composing a link with issue data in the source

    MediumCVSS 5.0No exploitEPSS 12%

    mantis · mantisOct 22, 2008

  • CVE-2004-1731
    21Monitor

    signup_page.php in Mantis bugtracker allows remote attackers to send e-mail bombs by creating multiple users and providing the same e-mail a

    MediumCVSS 5.0Proof of conceptEPSS 3%

    mantis · mantisAug 20, 2004

  • CVE-2005-4521
    21Monitor

    CRLF injection vulnerability in Mantis 1.0.0rc3 and earlier allows remote attackers to modify HTTP headers and conduct HTTP response splitti

    MediumCVSS 5.0No exploitEPSS 2%

    mantis · mantisDec 27, 2005

  • CVE-2005-4520
    21Monitor

    Unspecified "port injection" vulnerabilities in filters in Mantis 1.0.0rc3 and earlier have unknown impact and attack vectors.

    MediumCVSS 5.0No exploitEPSS 2%

    mantis · mantisDec 27, 2005

  • CVE-2006-6574
    21Monitor

    Mantis before 1.1.0a2 does not implement per-item access control for Issue History (Bug History), which allows remote attackers to obtain se

    MediumCVSS 5.0No exploitEPSS 2%

    mantis · mantisDec 15, 2006