mantis records
46 published records for vendor mantis.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 2.2%
- Pre-auth RCE
- 9
- With a fix record
- 69.6%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-287 Improper Authentication1
The weakness classes this vendor ships most often: where to look.
CWEAll records
46 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
56Plan | CVE-2008-4687Weaponized | manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort parameter containing PHP mantis · mantis · CWE-94 | Critical9.0 | — | 67.5% | Oct 22, 2008 |
41Plan | CVE-2002-1110No exploit | Multiple SQL injection vulnerabilities in Mantis 0.17.2 and earlier, when running without magic_quotes_gpc enabled, allows remote attackers mantis · mantis | Critical10.0 | — | 2.2% | Oct 4, 2002 |
41Plan | CVE-2006-0665No exploit | Unspecified vulnerability in (1) query_store.php and (2) manage_proj_create.php in Mantis before 1.0.0 has unknown impact and attack vectorsmantis · mantis | Critical10.0 | — | 1.8% | Feb 13, 2006 |
40Plan | CVE-2006-6515No exploit | Mantis before 1.1.0a2 sets the default value of $g_bug_reminder_threshold to "reporter" instead of a more privileged role, which has unknownmantis · mantis | Critical10.0 | — | 1.4% | Dec 13, 2006 |
34Monitor | CVE-2006-0146Proof of concept | The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Camantis · mantis · CWE-89 | High7.5 | — | 13.2% | Jan 9, 2006 |
34Monitor | CVE-2006-0147Proof of concept | Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (john lim · adodb | High7.5 | — | 13.1% | Jan 9, 2006 |
32Monitor | CVE-2005-3335No exploit | PHP file inclusion vulnerability in bug_sponsorship_list_view_inc.php in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbitmantis · mantis | High7.5 | — | 6.6% | Oct 27, 2005 |
31Monitor | CVE-2005-4518No exploit | Mantis before 0.19.4 allows remote attackers to bypass the file upload size restriction by modifying the max_file_size parameter to (1) bug_mantis · mantis | High7.5 | — | 3.7% | Dec 27, 2005 |
31Monitor | CVE-2002-1113Proof of concept | summary_graph_functions.php in Mantis 0.17.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the g_jpgraph_pamantis · mantis | High7.5 | — | 3.3% | Oct 4, 2002 |
31Monitor | CVE-2002-1114No exploit | config_inc2.php in Mantis before 0.17.4 allows remote attackers to execute arbitrary code or read arbitrary files via the parameters (1) g_bmantis · mantis | High7.5 | — | 2.8% | Oct 4, 2002 |
31Monitor | CVE-2008-4689No exploit | Mantis before 1.1.3 does not unset the session cookie during logout, which makes it easier for remote attackers to hijack sessions.mantis · mantis · CWE-287 | High7.5 | — | 2.5% | Oct 22, 2008 |
31Monitor | CVE-2008-3333No exploit | Directory traversal vulnerability in core/lang_api.php in Mantis before 1.1.2 allows remote attackers to include and execute arbitrary filesmantis · mantis · CWE-22 | High7.5 | — | 2.3% | Jul 27, 2008 |
31Monitor | CVE-2005-4519No exploit | Multiple SQL injection vulnerabilities in the manage user page (manage_user_page.php) in Mantis 1.0.0rc3 and earlier allow remote attackers mantis · mantis | High7.5 | — | 2.1% | Dec 27, 2005 |
31Monitor | CVE-2005-3336No exploit | SQL injection vulnerability in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbitrary SQL commands via unknown vectors.mantis · mantis | High7.5 | — | 1.9% | Oct 27, 2005 |
31Monitor | CVE-2004-1734No exploit | PHP remote file inclusion vulnerability in Mantis 0.19.0a allows remote attackers to execute arbitrary PHP code by modifying the (1) t_core_mantis · mantis | High7.5 | — | 1.7% | Dec 31, 2004 |
30Monitor | CVE-2005-2556No exploit | core/database_api.php in Mantis 0.19.0a1 through 1.0.0a3, with register_globals enabled, allows remote attackers to connect to internal datamantis · mantis | High7.5 | — | 1.6% | Aug 24, 2005 |
30Monitor | CVE-2002-1116No exploit | The "View Bugs" page (view_all_bug_page.php) in Mantis 0.17.4a and earlier includes summaries of private bugs for users that do not have accmantis · mantis | High7.5 | — | 1.4% | Oct 4, 2002 |
29Monitor | CVE-2008-3332Proof of concept | Eval injection vulnerability in adm_config_set.php in Mantis before 1.1.2 allows remote authenticated administrators to execute arbitrary comantis · mantis · CWE-94 | Medium6.5 | — | 9.5% | Jul 27, 2008 |
28Monitor | CVE-2006-1577No exploit | Multiple cross-site scripting (XSS) vulnerabilities in view_all_set.php in Mantis 1.0.1, 1.0.0rc5, and earlier allow remote attackers to injmantis · mantis | Medium6.8 | — | 1.8% | Apr 2, 2006 |
28Monitor | CVE-2005-3339No exploit | Mantis before 0.19.3 caches the User ID longer than necessary, which has unknown impact and attack vectors.mantis · mantis | High7.2 | — | 0.4% | Oct 27, 2005 |
24Monitor | CVE-2008-4688No exploit | core/string_api.php in Mantis before 1.1.3 does not check the privileges of the viewer before composing a link with issue data in the sourcemantis · mantis · CWE-200 | Medium5.0 | — | 11.7% | Oct 22, 2008 |
21Monitor | CVE-2004-1731Proof of concept | signup_page.php in Mantis bugtracker allows remote attackers to send e-mail bombs by creating multiple users and providing the same e-mail amantis · mantis | Medium5.0 | — | 3.2% | Aug 20, 2004 |
21Monitor | CVE-2005-4521No exploit | CRLF injection vulnerability in Mantis 1.0.0rc3 and earlier allows remote attackers to modify HTTP headers and conduct HTTP response splittimantis · mantis | Medium5.0 | — | 2.2% | Dec 27, 2005 |
21Monitor | CVE-2005-4520No exploit | Unspecified "port injection" vulnerabilities in filters in Mantis 1.0.0rc3 and earlier have unknown impact and attack vectors.mantis · mantis | Medium5.0 | — | 2.1% | Dec 27, 2005 |
21Monitor | CVE-2006-6574No exploit | Mantis before 1.1.0a2 does not implement per-item access control for Issue History (Bug History), which allows remote attackers to obtain semantis · mantis | Medium5.0 | — | 2.0% | Dec 15, 2006 |
- CVE-2008-468756Plan
manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort parameter containing PHP
CriticalCVSS 9.0WeaponizedEPSS 67%mantis · mantisOct 22, 2008
- CVE-2002-111041Plan
Multiple SQL injection vulnerabilities in Mantis 0.17.2 and earlier, when running without magic_quotes_gpc enabled, allows remote attackers
CriticalCVSS 10.0No exploitEPSS 2%mantis · mantisOct 4, 2002
- CVE-2006-066541Plan
Unspecified vulnerability in (1) query_store.php and (2) manage_proj_create.php in Mantis before 1.0.0 has unknown impact and attack vectors
CriticalCVSS 10.0No exploitEPSS 2%mantis · mantisFeb 13, 2006
- CVE-2006-651540Plan
Mantis before 1.1.0a2 sets the default value of $g_bug_reminder_threshold to "reporter" instead of a more privileged role, which has unknown
CriticalCVSS 10.0No exploitEPSS 1%mantis · mantisDec 13, 2006
- CVE-2006-014634Monitor
The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Ca
HighCVSS 7.5Proof of conceptEPSS 13%mantis · mantisJan 9, 2006
- CVE-2006-014734Monitor
Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (
HighCVSS 7.5Proof of conceptEPSS 13%john lim · adodbJan 9, 2006
- CVE-2005-333532Monitor
PHP file inclusion vulnerability in bug_sponsorship_list_view_inc.php in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbit
HighCVSS 7.5No exploitEPSS 7%mantis · mantisOct 27, 2005
- CVE-2005-451831Monitor
Mantis before 0.19.4 allows remote attackers to bypass the file upload size restriction by modifying the max_file_size parameter to (1) bug_
HighCVSS 7.5No exploitEPSS 4%mantis · mantisDec 27, 2005
- CVE-2002-111331Monitor
summary_graph_functions.php in Mantis 0.17.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the g_jpgraph_pa
HighCVSS 7.5Proof of conceptEPSS 3%mantis · mantisOct 4, 2002
- CVE-2002-111431Monitor
config_inc2.php in Mantis before 0.17.4 allows remote attackers to execute arbitrary code or read arbitrary files via the parameters (1) g_b
HighCVSS 7.5No exploitEPSS 3%mantis · mantisOct 4, 2002
- CVE-2008-468931Monitor
Mantis before 1.1.3 does not unset the session cookie during logout, which makes it easier for remote attackers to hijack sessions.
HighCVSS 7.5No exploitEPSS 2%mantis · mantisOct 22, 2008
- CVE-2008-333331Monitor
Directory traversal vulnerability in core/lang_api.php in Mantis before 1.1.2 allows remote attackers to include and execute arbitrary files
HighCVSS 7.5No exploitEPSS 2%mantis · mantisJul 27, 2008
- CVE-2005-451931Monitor
Multiple SQL injection vulnerabilities in the manage user page (manage_user_page.php) in Mantis 1.0.0rc3 and earlier allow remote attackers
HighCVSS 7.5No exploitEPSS 2%mantis · mantisDec 27, 2005
- CVE-2005-333631Monitor
SQL injection vulnerability in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
HighCVSS 7.5No exploitEPSS 2%mantis · mantisOct 27, 2005
- CVE-2004-173431Monitor
PHP remote file inclusion vulnerability in Mantis 0.19.0a allows remote attackers to execute arbitrary PHP code by modifying the (1) t_core_
HighCVSS 7.5No exploitEPSS 2%mantis · mantisDec 31, 2004
- CVE-2005-255630Monitor
core/database_api.php in Mantis 0.19.0a1 through 1.0.0a3, with register_globals enabled, allows remote attackers to connect to internal data
HighCVSS 7.5No exploitEPSS 2%mantis · mantisAug 24, 2005
- CVE-2002-111630Monitor
The "View Bugs" page (view_all_bug_page.php) in Mantis 0.17.4a and earlier includes summaries of private bugs for users that do not have acc
HighCVSS 7.5No exploitEPSS 1%mantis · mantisOct 4, 2002
- CVE-2008-333229Monitor
Eval injection vulnerability in adm_config_set.php in Mantis before 1.1.2 allows remote authenticated administrators to execute arbitrary co
MediumCVSS 6.5Proof of conceptEPSS 9%mantis · mantisJul 27, 2008
- CVE-2006-157728Monitor
Multiple cross-site scripting (XSS) vulnerabilities in view_all_set.php in Mantis 1.0.1, 1.0.0rc5, and earlier allow remote attackers to inj
MediumCVSS 6.8No exploitEPSS 2%mantis · mantisApr 2, 2006
- CVE-2005-333928Monitor
Mantis before 0.19.3 caches the User ID longer than necessary, which has unknown impact and attack vectors.
HighCVSS 7.2No exploitEPSS 0%mantis · mantisOct 27, 2005
- CVE-2008-468824Monitor
core/string_api.php in Mantis before 1.1.3 does not check the privileges of the viewer before composing a link with issue data in the source
MediumCVSS 5.0No exploitEPSS 12%mantis · mantisOct 22, 2008
- CVE-2004-173121Monitor
signup_page.php in Mantis bugtracker allows remote attackers to send e-mail bombs by creating multiple users and providing the same e-mail a
MediumCVSS 5.0Proof of conceptEPSS 3%mantis · mantisAug 20, 2004
- CVE-2005-452121Monitor
CRLF injection vulnerability in Mantis 1.0.0rc3 and earlier allows remote attackers to modify HTTP headers and conduct HTTP response splitti
MediumCVSS 5.0No exploitEPSS 2%mantis · mantisDec 27, 2005
- CVE-2005-452021Monitor
Unspecified "port injection" vulnerabilities in filters in Mantis 1.0.0rc3 and earlier have unknown impact and attack vectors.
MediumCVSS 5.0No exploitEPSS 2%mantis · mantisDec 27, 2005
- CVE-2006-657421Monitor
Mantis before 1.1.0a2 does not implement per-item access control for Issue History (Bug History), which allows remote attackers to obtain se
MediumCVSS 5.0No exploitEPSS 2%mantis · mantisDec 15, 2006