Записи mantis
46 опубликованных записей вендора mantis.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 2,2 %
- Pre-auth RCE
- 9
- С записью об исправлении
- 69,6 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-287 Improper Authentication1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
46 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
56В плане | CVE-2008-4687Готовый эксплойт | manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort parameter containing PHP mantis · mantis · CWE-94 | Критическая9,0 | — | 67,5 % | 22 окт. 2008 г. |
41В плане | CVE-2002-1110Эксплойта нет | Multiple SQL injection vulnerabilities in Mantis 0.17.2 and earlier, when running without magic_quotes_gpc enabled, allows remote attackers mantis · mantis | Критическая10,0 | — | 2,2 % | 4 окт. 2002 г. |
41В плане | CVE-2006-0665Эксплойта нет | Unspecified vulnerability in (1) query_store.php and (2) manage_proj_create.php in Mantis before 1.0.0 has unknown impact and attack vectorsmantis · mantis | Критическая10,0 | — | 1,8 % | 13 февр. 2006 г. |
40В плане | CVE-2006-6515Эксплойта нет | Mantis before 1.1.0a2 sets the default value of $g_bug_reminder_threshold to "reporter" instead of a more privileged role, which has unknownmantis · mantis | Критическая10,0 | — | 1,4 % | 13 дек. 2006 г. |
34Наблюдать | CVE-2006-0146Proof of concept | The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Camantis · mantis · CWE-89 | Высокая7,5 | — | 13,2 % | 9 янв. 2006 г. |
34Наблюдать | CVE-2006-0147Proof of concept | Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (john lim · adodb | Высокая7,5 | — | 13,1 % | 9 янв. 2006 г. |
32Наблюдать | CVE-2005-3335Эксплойта нет | PHP file inclusion vulnerability in bug_sponsorship_list_view_inc.php in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbitmantis · mantis | Высокая7,5 | — | 6,6 % | 27 окт. 2005 г. |
31Наблюдать | CVE-2005-4518Эксплойта нет | Mantis before 0.19.4 allows remote attackers to bypass the file upload size restriction by modifying the max_file_size parameter to (1) bug_mantis · mantis | Высокая7,5 | — | 3,7 % | 27 дек. 2005 г. |
31Наблюдать | CVE-2002-1113Proof of concept | summary_graph_functions.php in Mantis 0.17.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the g_jpgraph_pamantis · mantis | Высокая7,5 | — | 3,3 % | 4 окт. 2002 г. |
31Наблюдать | CVE-2002-1114Эксплойта нет | config_inc2.php in Mantis before 0.17.4 allows remote attackers to execute arbitrary code or read arbitrary files via the parameters (1) g_bmantis · mantis | Высокая7,5 | — | 2,8 % | 4 окт. 2002 г. |
31Наблюдать | CVE-2008-4689Эксплойта нет | Mantis before 1.1.3 does not unset the session cookie during logout, which makes it easier for remote attackers to hijack sessions.mantis · mantis · CWE-287 | Высокая7,5 | — | 2,5 % | 22 окт. 2008 г. |
31Наблюдать | CVE-2008-3333Эксплойта нет | Directory traversal vulnerability in core/lang_api.php in Mantis before 1.1.2 allows remote attackers to include and execute arbitrary filesmantis · mantis · CWE-22 | Высокая7,5 | — | 2,3 % | 27 июл. 2008 г. |
31Наблюдать | CVE-2005-4519Эксплойта нет | Multiple SQL injection vulnerabilities in the manage user page (manage_user_page.php) in Mantis 1.0.0rc3 and earlier allow remote attackers mantis · mantis | Высокая7,5 | — | 2,1 % | 27 дек. 2005 г. |
31Наблюдать | CVE-2005-3336Эксплойта нет | SQL injection vulnerability in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbitrary SQL commands via unknown vectors.mantis · mantis | Высокая7,5 | — | 1,9 % | 27 окт. 2005 г. |
31Наблюдать | CVE-2004-1734Эксплойта нет | PHP remote file inclusion vulnerability in Mantis 0.19.0a allows remote attackers to execute arbitrary PHP code by modifying the (1) t_core_mantis · mantis | Высокая7,5 | — | 1,7 % | 31 дек. 2004 г. |
30Наблюдать | CVE-2005-2556Эксплойта нет | core/database_api.php in Mantis 0.19.0a1 through 1.0.0a3, with register_globals enabled, allows remote attackers to connect to internal datamantis · mantis | Высокая7,5 | — | 1,6 % | 24 авг. 2005 г. |
30Наблюдать | CVE-2002-1116Эксплойта нет | The "View Bugs" page (view_all_bug_page.php) in Mantis 0.17.4a and earlier includes summaries of private bugs for users that do not have accmantis · mantis | Высокая7,5 | — | 1,4 % | 4 окт. 2002 г. |
29Наблюдать | CVE-2008-3332Proof of concept | Eval injection vulnerability in adm_config_set.php in Mantis before 1.1.2 allows remote authenticated administrators to execute arbitrary comantis · mantis · CWE-94 | Средняя6,5 | — | 9,5 % | 27 июл. 2008 г. |
28Наблюдать | CVE-2006-1577Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in view_all_set.php in Mantis 1.0.1, 1.0.0rc5, and earlier allow remote attackers to injmantis · mantis | Средняя6,8 | — | 1,8 % | 2 апр. 2006 г. |
28Наблюдать | CVE-2005-3339Эксплойта нет | Mantis before 0.19.3 caches the User ID longer than necessary, which has unknown impact and attack vectors.mantis · mantis | Высокая7,2 | — | 0,4 % | 27 окт. 2005 г. |
24Наблюдать | CVE-2008-4688Эксплойта нет | core/string_api.php in Mantis before 1.1.3 does not check the privileges of the viewer before composing a link with issue data in the sourcemantis · mantis · CWE-200 | Средняя5,0 | — | 11,7 % | 22 окт. 2008 г. |
21Наблюдать | CVE-2004-1731Proof of concept | signup_page.php in Mantis bugtracker allows remote attackers to send e-mail bombs by creating multiple users and providing the same e-mail amantis · mantis | Средняя5,0 | — | 3,2 % | 20 авг. 2004 г. |
21Наблюдать | CVE-2005-4521Эксплойта нет | CRLF injection vulnerability in Mantis 1.0.0rc3 and earlier allows remote attackers to modify HTTP headers and conduct HTTP response splittimantis · mantis | Средняя5,0 | — | 2,2 % | 27 дек. 2005 г. |
21Наблюдать | CVE-2005-4520Эксплойта нет | Unspecified "port injection" vulnerabilities in filters in Mantis 1.0.0rc3 and earlier have unknown impact and attack vectors.mantis · mantis | Средняя5,0 | — | 2,1 % | 27 дек. 2005 г. |
21Наблюдать | CVE-2006-6574Эксплойта нет | Mantis before 1.1.0a2 does not implement per-item access control for Issue History (Bug History), which allows remote attackers to obtain semantis · mantis | Средняя5,0 | — | 2,0 % | 15 дек. 2006 г. |
- CVE-2008-468756В плане
manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort parameter containing PHP
КритическаяCVSS 9,0Готовый эксплойтEPSS 67 %mantis · mantis22 окт. 2008 г.
- CVE-2002-111041В плане
Multiple SQL injection vulnerabilities in Mantis 0.17.2 and earlier, when running without magic_quotes_gpc enabled, allows remote attackers
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %mantis · mantis4 окт. 2002 г.
- CVE-2006-066541В плане
Unspecified vulnerability in (1) query_store.php and (2) manage_proj_create.php in Mantis before 1.0.0 has unknown impact and attack vectors
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %mantis · mantis13 февр. 2006 г.
- CVE-2006-651540В плане
Mantis before 1.1.0a2 sets the default value of $g_bug_reminder_threshold to "reporter" instead of a more privileged role, which has unknown
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %mantis · mantis13 дек. 2006 г.
- CVE-2006-014634Наблюдать
The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Ca
ВысокаяCVSS 7,5Proof of conceptEPSS 13 %mantis · mantis9 янв. 2006 г.
- CVE-2006-014734Наблюдать
Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (
ВысокаяCVSS 7,5Proof of conceptEPSS 13 %john lim · adodb9 янв. 2006 г.
- CVE-2005-333532Наблюдать
PHP file inclusion vulnerability in bug_sponsorship_list_view_inc.php in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbit
ВысокаяCVSS 7,5Эксплойта нетEPSS 7 %mantis · mantis27 окт. 2005 г.
- CVE-2005-451831Наблюдать
Mantis before 0.19.4 allows remote attackers to bypass the file upload size restriction by modifying the max_file_size parameter to (1) bug_
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %mantis · mantis27 дек. 2005 г.
- CVE-2002-111331Наблюдать
summary_graph_functions.php in Mantis 0.17.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the g_jpgraph_pa
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %mantis · mantis4 окт. 2002 г.
- CVE-2002-111431Наблюдать
config_inc2.php in Mantis before 0.17.4 allows remote attackers to execute arbitrary code or read arbitrary files via the parameters (1) g_b
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %mantis · mantis4 окт. 2002 г.
- CVE-2008-468931Наблюдать
Mantis before 1.1.3 does not unset the session cookie during logout, which makes it easier for remote attackers to hijack sessions.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %mantis · mantis22 окт. 2008 г.
- CVE-2008-333331Наблюдать
Directory traversal vulnerability in core/lang_api.php in Mantis before 1.1.2 allows remote attackers to include and execute arbitrary files
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %mantis · mantis27 июл. 2008 г.
- CVE-2005-451931Наблюдать
Multiple SQL injection vulnerabilities in the manage user page (manage_user_page.php) in Mantis 1.0.0rc3 and earlier allow remote attackers
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %mantis · mantis27 дек. 2005 г.
- CVE-2005-333631Наблюдать
SQL injection vulnerability in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %mantis · mantis27 окт. 2005 г.
- CVE-2004-173431Наблюдать
PHP remote file inclusion vulnerability in Mantis 0.19.0a allows remote attackers to execute arbitrary PHP code by modifying the (1) t_core_
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %mantis · mantis31 дек. 2004 г.
- CVE-2005-255630Наблюдать
core/database_api.php in Mantis 0.19.0a1 through 1.0.0a3, with register_globals enabled, allows remote attackers to connect to internal data
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %mantis · mantis24 авг. 2005 г.
- CVE-2002-111630Наблюдать
The "View Bugs" page (view_all_bug_page.php) in Mantis 0.17.4a and earlier includes summaries of private bugs for users that do not have acc
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %mantis · mantis4 окт. 2002 г.
- CVE-2008-333229Наблюдать
Eval injection vulnerability in adm_config_set.php in Mantis before 1.1.2 allows remote authenticated administrators to execute arbitrary co
СредняяCVSS 6,5Proof of conceptEPSS 9 %mantis · mantis27 июл. 2008 г.
- CVE-2006-157728Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in view_all_set.php in Mantis 1.0.1, 1.0.0rc5, and earlier allow remote attackers to inj
СредняяCVSS 6,8Эксплойта нетEPSS 2 %mantis · mantis2 апр. 2006 г.
- CVE-2005-333928Наблюдать
Mantis before 0.19.3 caches the User ID longer than necessary, which has unknown impact and attack vectors.
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %mantis · mantis27 окт. 2005 г.
- CVE-2008-468824Наблюдать
core/string_api.php in Mantis before 1.1.3 does not check the privileges of the viewer before composing a link with issue data in the source
СредняяCVSS 5,0Эксплойта нетEPSS 12 %mantis · mantis22 окт. 2008 г.
- CVE-2004-173121Наблюдать
signup_page.php in Mantis bugtracker allows remote attackers to send e-mail bombs by creating multiple users and providing the same e-mail a
СредняяCVSS 5,0Proof of conceptEPSS 3 %mantis · mantis20 авг. 2004 г.
- CVE-2005-452121Наблюдать
CRLF injection vulnerability in Mantis 1.0.0rc3 and earlier allows remote attackers to modify HTTP headers and conduct HTTP response splitti
СредняяCVSS 5,0Эксплойта нетEPSS 2 %mantis · mantis27 дек. 2005 г.
- CVE-2005-452021Наблюдать
Unspecified "port injection" vulnerabilities in filters in Mantis 1.0.0rc3 and earlier have unknown impact and attack vectors.
СредняяCVSS 5,0Эксплойта нетEPSS 2 %mantis · mantis27 дек. 2005 г.
- CVE-2006-657421Наблюдать
Mantis before 1.1.0a2 does not implement per-item access control for Issue History (Bug History), which allows remote attackers to obtain se
СредняяCVSS 5,0Эксплойта нетEPSS 2 %mantis · mantis15 дек. 2006 г.