Перейти к содержимому
Noroxi

Записи mantis

46 опубликованных записей вендора mantis.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
1 · 2,2 %
Pre-auth RCE
9
С записью об исправлении
69,6 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

46 записей
  • CVE-2008-4687
    56В плане

    manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort parameter containing PHP

    КритическаяCVSS 9,0Готовый эксплойтEPSS 67 %

    mantis · mantis22 окт. 2008 г.

  • CVE-2002-1110
    41В плане

    Multiple SQL injection vulnerabilities in Mantis 0.17.2 and earlier, when running without magic_quotes_gpc enabled, allows remote attackers

    КритическаяCVSS 10,0Эксплойта нетEPSS 2 %

    mantis · mantis4 окт. 2002 г.

  • CVE-2006-0665
    41В плане

    Unspecified vulnerability in (1) query_store.php and (2) manage_proj_create.php in Mantis before 1.0.0 has unknown impact and attack vectors

    КритическаяCVSS 10,0Эксплойта нетEPSS 2 %

    mantis · mantis13 февр. 2006 г.

  • CVE-2006-6515
    40В плане

    Mantis before 1.1.0a2 sets the default value of $g_bug_reminder_threshold to "reporter" instead of a more privileged role, which has unknown

    КритическаяCVSS 10,0Эксплойта нетEPSS 1 %

    mantis · mantis13 дек. 2006 г.

  • CVE-2006-0146
    34Наблюдать

    The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Ca

    ВысокаяCVSS 7,5Proof of conceptEPSS 13 %

    mantis · mantis9 янв. 2006 г.

  • CVE-2006-0147
    34Наблюдать

    Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (

    ВысокаяCVSS 7,5Proof of conceptEPSS 13 %

    john lim · adodb9 янв. 2006 г.

  • CVE-2005-3335
    32Наблюдать

    PHP file inclusion vulnerability in bug_sponsorship_list_view_inc.php in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbit

    ВысокаяCVSS 7,5Эксплойта нетEPSS 7 %

    mantis · mantis27 окт. 2005 г.

  • CVE-2005-4518
    31Наблюдать

    Mantis before 0.19.4 allows remote attackers to bypass the file upload size restriction by modifying the max_file_size parameter to (1) bug_

    ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %

    mantis · mantis27 дек. 2005 г.

  • CVE-2002-1113
    31Наблюдать

    summary_graph_functions.php in Mantis 0.17.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the g_jpgraph_pa

    ВысокаяCVSS 7,5Proof of conceptEPSS 3 %

    mantis · mantis4 окт. 2002 г.

  • CVE-2002-1114
    31Наблюдать

    config_inc2.php in Mantis before 0.17.4 allows remote attackers to execute arbitrary code or read arbitrary files via the parameters (1) g_b

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    mantis · mantis4 окт. 2002 г.

  • CVE-2008-4689
    31Наблюдать

    Mantis before 1.1.3 does not unset the session cookie during logout, which makes it easier for remote attackers to hijack sessions.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    mantis · mantis22 окт. 2008 г.

  • CVE-2008-3333
    31Наблюдать

    Directory traversal vulnerability in core/lang_api.php in Mantis before 1.1.2 allows remote attackers to include and execute arbitrary files

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    mantis · mantis27 июл. 2008 г.

  • CVE-2005-4519
    31Наблюдать

    Multiple SQL injection vulnerabilities in the manage user page (manage_user_page.php) in Mantis 1.0.0rc3 and earlier allow remote attackers

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    mantis · mantis27 дек. 2005 г.

  • CVE-2005-3336
    31Наблюдать

    SQL injection vulnerability in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    mantis · mantis27 окт. 2005 г.

  • CVE-2004-1734
    31Наблюдать

    PHP remote file inclusion vulnerability in Mantis 0.19.0a allows remote attackers to execute arbitrary PHP code by modifying the (1) t_core_

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    mantis · mantis31 дек. 2004 г.

  • CVE-2005-2556
    30Наблюдать

    core/database_api.php in Mantis 0.19.0a1 through 1.0.0a3, with register_globals enabled, allows remote attackers to connect to internal data

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    mantis · mantis24 авг. 2005 г.

  • CVE-2002-1116
    30Наблюдать

    The "View Bugs" page (view_all_bug_page.php) in Mantis 0.17.4a and earlier includes summaries of private bugs for users that do not have acc

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    mantis · mantis4 окт. 2002 г.

  • CVE-2008-3332
    29Наблюдать

    Eval injection vulnerability in adm_config_set.php in Mantis before 1.1.2 allows remote authenticated administrators to execute arbitrary co

    СредняяCVSS 6,5Proof of conceptEPSS 9 %

    mantis · mantis27 июл. 2008 г.

  • CVE-2006-1577
    28Наблюдать

    Multiple cross-site scripting (XSS) vulnerabilities in view_all_set.php in Mantis 1.0.1, 1.0.0rc5, and earlier allow remote attackers to inj

    СредняяCVSS 6,8Эксплойта нетEPSS 2 %

    mantis · mantis2 апр. 2006 г.

  • CVE-2005-3339
    28Наблюдать

    Mantis before 0.19.3 caches the User ID longer than necessary, which has unknown impact and attack vectors.

    ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %

    mantis · mantis27 окт. 2005 г.

  • CVE-2008-4688
    24Наблюдать

    core/string_api.php in Mantis before 1.1.3 does not check the privileges of the viewer before composing a link with issue data in the source

    СредняяCVSS 5,0Эксплойта нетEPSS 12 %

    mantis · mantis22 окт. 2008 г.

  • CVE-2004-1731
    21Наблюдать

    signup_page.php in Mantis bugtracker allows remote attackers to send e-mail bombs by creating multiple users and providing the same e-mail a

    СредняяCVSS 5,0Proof of conceptEPSS 3 %

    mantis · mantis20 авг. 2004 г.

  • CVE-2005-4521
    21Наблюдать

    CRLF injection vulnerability in Mantis 1.0.0rc3 and earlier allows remote attackers to modify HTTP headers and conduct HTTP response splitti

    СредняяCVSS 5,0Эксплойта нетEPSS 2 %

    mantis · mantis27 дек. 2005 г.

  • CVE-2005-4520
    21Наблюдать

    Unspecified "port injection" vulnerabilities in filters in Mantis 1.0.0rc3 and earlier have unknown impact and attack vectors.

    СредняяCVSS 5,0Эксплойта нетEPSS 2 %

    mantis · mantis27 дек. 2005 г.

  • CVE-2006-6574
    21Наблюдать

    Mantis before 1.1.0a2 does not implement per-item access control for Issue History (Bug History), which allows remote attackers to obtain se

    СредняяCVSS 5,0Эксплойта нетEPSS 2 %

    mantis · mantis15 дек. 2006 г.