mantis kayıtları
mantis üreticisine ait 46 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %2,2
- Pre-auth RCE
- 9
- Düzeltme kaydı olan
- %69,6
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-287 Improper Authentication1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
46 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
56Planlayın | CVE-2008-4687Silahlaştırılmış | manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort parameter containing PHP mantis · mantis · CWE-94 | Kritik9,0 | — | %67,5 | 22 Eki 2008 |
41Planlayın | CVE-2002-1110İstismar yok | Multiple SQL injection vulnerabilities in Mantis 0.17.2 and earlier, when running without magic_quotes_gpc enabled, allows remote attackers mantis · mantis | Kritik10,0 | — | %2,2 | 4 Eki 2002 |
41Planlayın | CVE-2006-0665İstismar yok | Unspecified vulnerability in (1) query_store.php and (2) manage_proj_create.php in Mantis before 1.0.0 has unknown impact and attack vectorsmantis · mantis | Kritik10,0 | — | %1,8 | 13 Şub 2006 |
40Planlayın | CVE-2006-6515İstismar yok | Mantis before 1.1.0a2 sets the default value of $g_bug_reminder_threshold to "reporter" instead of a more privileged role, which has unknownmantis · mantis | Kritik10,0 | — | %1,4 | 13 Ara 2006 |
34İzleyin | CVE-2006-0146Kavram kanıtı | The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Camantis · mantis · CWE-89 | Yüksek7,5 | — | %13,2 | 9 Oca 2006 |
34İzleyin | CVE-2006-0147Kavram kanıtı | Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (john lim · adodb | Yüksek7,5 | — | %13,1 | 9 Oca 2006 |
32İzleyin | CVE-2005-3335İstismar yok | PHP file inclusion vulnerability in bug_sponsorship_list_view_inc.php in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbitmantis · mantis | Yüksek7,5 | — | %6,6 | 27 Eki 2005 |
31İzleyin | CVE-2005-4518İstismar yok | Mantis before 0.19.4 allows remote attackers to bypass the file upload size restriction by modifying the max_file_size parameter to (1) bug_mantis · mantis | Yüksek7,5 | — | %3,7 | 27 Ara 2005 |
31İzleyin | CVE-2002-1113Kavram kanıtı | summary_graph_functions.php in Mantis 0.17.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the g_jpgraph_pamantis · mantis | Yüksek7,5 | — | %3,3 | 4 Eki 2002 |
31İzleyin | CVE-2002-1114İstismar yok | config_inc2.php in Mantis before 0.17.4 allows remote attackers to execute arbitrary code or read arbitrary files via the parameters (1) g_bmantis · mantis | Yüksek7,5 | — | %2,8 | 4 Eki 2002 |
31İzleyin | CVE-2008-4689İstismar yok | Mantis before 1.1.3 does not unset the session cookie during logout, which makes it easier for remote attackers to hijack sessions.mantis · mantis · CWE-287 | Yüksek7,5 | — | %2,5 | 22 Eki 2008 |
31İzleyin | CVE-2008-3333İstismar yok | Directory traversal vulnerability in core/lang_api.php in Mantis before 1.1.2 allows remote attackers to include and execute arbitrary filesmantis · mantis · CWE-22 | Yüksek7,5 | — | %2,3 | 27 Tem 2008 |
31İzleyin | CVE-2005-4519İstismar yok | Multiple SQL injection vulnerabilities in the manage user page (manage_user_page.php) in Mantis 1.0.0rc3 and earlier allow remote attackers mantis · mantis | Yüksek7,5 | — | %2,1 | 27 Ara 2005 |
31İzleyin | CVE-2005-3336İstismar yok | SQL injection vulnerability in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbitrary SQL commands via unknown vectors.mantis · mantis | Yüksek7,5 | — | %1,9 | 27 Eki 2005 |
31İzleyin | CVE-2004-1734İstismar yok | PHP remote file inclusion vulnerability in Mantis 0.19.0a allows remote attackers to execute arbitrary PHP code by modifying the (1) t_core_mantis · mantis | Yüksek7,5 | — | %1,7 | 31 Ara 2004 |
30İzleyin | CVE-2005-2556İstismar yok | core/database_api.php in Mantis 0.19.0a1 through 1.0.0a3, with register_globals enabled, allows remote attackers to connect to internal datamantis · mantis | Yüksek7,5 | — | %1,6 | 24 Ağu 2005 |
30İzleyin | CVE-2002-1116İstismar yok | The "View Bugs" page (view_all_bug_page.php) in Mantis 0.17.4a and earlier includes summaries of private bugs for users that do not have accmantis · mantis | Yüksek7,5 | — | %1,4 | 4 Eki 2002 |
29İzleyin | CVE-2008-3332Kavram kanıtı | Eval injection vulnerability in adm_config_set.php in Mantis before 1.1.2 allows remote authenticated administrators to execute arbitrary comantis · mantis · CWE-94 | Orta6,5 | — | %9,5 | 27 Tem 2008 |
28İzleyin | CVE-2006-1577İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in view_all_set.php in Mantis 1.0.1, 1.0.0rc5, and earlier allow remote attackers to injmantis · mantis | Orta6,8 | — | %1,8 | 2 Nis 2006 |
28İzleyin | CVE-2005-3339İstismar yok | Mantis before 0.19.3 caches the User ID longer than necessary, which has unknown impact and attack vectors.mantis · mantis | Yüksek7,2 | — | %0,4 | 27 Eki 2005 |
24İzleyin | CVE-2008-4688İstismar yok | core/string_api.php in Mantis before 1.1.3 does not check the privileges of the viewer before composing a link with issue data in the sourcemantis · mantis · CWE-200 | Orta5,0 | — | %11,7 | 22 Eki 2008 |
21İzleyin | CVE-2004-1731Kavram kanıtı | signup_page.php in Mantis bugtracker allows remote attackers to send e-mail bombs by creating multiple users and providing the same e-mail amantis · mantis | Orta5,0 | — | %3,2 | 20 Ağu 2004 |
21İzleyin | CVE-2005-4521İstismar yok | CRLF injection vulnerability in Mantis 1.0.0rc3 and earlier allows remote attackers to modify HTTP headers and conduct HTTP response splittimantis · mantis | Orta5,0 | — | %2,2 | 27 Ara 2005 |
21İzleyin | CVE-2005-4520İstismar yok | Unspecified "port injection" vulnerabilities in filters in Mantis 1.0.0rc3 and earlier have unknown impact and attack vectors.mantis · mantis | Orta5,0 | — | %2,1 | 27 Ara 2005 |
21İzleyin | CVE-2006-6574İstismar yok | Mantis before 1.1.0a2 does not implement per-item access control for Issue History (Bug History), which allows remote attackers to obtain semantis · mantis | Orta5,0 | — | %2,0 | 15 Ara 2006 |
- CVE-2008-468756Planlayın
manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort parameter containing PHP
KritikCVSS 9,0SilahlaştırılmışEPSS %67mantis · mantis22 Eki 2008
- CVE-2002-111041Planlayın
Multiple SQL injection vulnerabilities in Mantis 0.17.2 and earlier, when running without magic_quotes_gpc enabled, allows remote attackers
KritikCVSS 10,0İstismar yokEPSS %2mantis · mantis4 Eki 2002
- CVE-2006-066541Planlayın
Unspecified vulnerability in (1) query_store.php and (2) manage_proj_create.php in Mantis before 1.0.0 has unknown impact and attack vectors
KritikCVSS 10,0İstismar yokEPSS %2mantis · mantis13 Şub 2006
- CVE-2006-651540Planlayın
Mantis before 1.1.0a2 sets the default value of $g_bug_reminder_threshold to "reporter" instead of a more privileged role, which has unknown
KritikCVSS 10,0İstismar yokEPSS %1mantis · mantis13 Ara 2006
- CVE-2006-014634İzleyin
The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Ca
YüksekCVSS 7,5Kavram kanıtıEPSS %13mantis · mantis9 Oca 2006
- CVE-2006-014734İzleyin
Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (
YüksekCVSS 7,5Kavram kanıtıEPSS %13john lim · adodb9 Oca 2006
- CVE-2005-333532İzleyin
PHP file inclusion vulnerability in bug_sponsorship_list_view_inc.php in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbit
YüksekCVSS 7,5İstismar yokEPSS %7mantis · mantis27 Eki 2005
- CVE-2005-451831İzleyin
Mantis before 0.19.4 allows remote attackers to bypass the file upload size restriction by modifying the max_file_size parameter to (1) bug_
YüksekCVSS 7,5İstismar yokEPSS %4mantis · mantis27 Ara 2005
- CVE-2002-111331İzleyin
summary_graph_functions.php in Mantis 0.17.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the g_jpgraph_pa
YüksekCVSS 7,5Kavram kanıtıEPSS %3mantis · mantis4 Eki 2002
- CVE-2002-111431İzleyin
config_inc2.php in Mantis before 0.17.4 allows remote attackers to execute arbitrary code or read arbitrary files via the parameters (1) g_b
YüksekCVSS 7,5İstismar yokEPSS %3mantis · mantis4 Eki 2002
- CVE-2008-468931İzleyin
Mantis before 1.1.3 does not unset the session cookie during logout, which makes it easier for remote attackers to hijack sessions.
YüksekCVSS 7,5İstismar yokEPSS %2mantis · mantis22 Eki 2008
- CVE-2008-333331İzleyin
Directory traversal vulnerability in core/lang_api.php in Mantis before 1.1.2 allows remote attackers to include and execute arbitrary files
YüksekCVSS 7,5İstismar yokEPSS %2mantis · mantis27 Tem 2008
- CVE-2005-451931İzleyin
Multiple SQL injection vulnerabilities in the manage user page (manage_user_page.php) in Mantis 1.0.0rc3 and earlier allow remote attackers
YüksekCVSS 7,5İstismar yokEPSS %2mantis · mantis27 Ara 2005
- CVE-2005-333631İzleyin
SQL injection vulnerability in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
YüksekCVSS 7,5İstismar yokEPSS %2mantis · mantis27 Eki 2005
- CVE-2004-173431İzleyin
PHP remote file inclusion vulnerability in Mantis 0.19.0a allows remote attackers to execute arbitrary PHP code by modifying the (1) t_core_
YüksekCVSS 7,5İstismar yokEPSS %2mantis · mantis31 Ara 2004
- CVE-2005-255630İzleyin
core/database_api.php in Mantis 0.19.0a1 through 1.0.0a3, with register_globals enabled, allows remote attackers to connect to internal data
YüksekCVSS 7,5İstismar yokEPSS %2mantis · mantis24 Ağu 2005
- CVE-2002-111630İzleyin
The "View Bugs" page (view_all_bug_page.php) in Mantis 0.17.4a and earlier includes summaries of private bugs for users that do not have acc
YüksekCVSS 7,5İstismar yokEPSS %1mantis · mantis4 Eki 2002
- CVE-2008-333229İzleyin
Eval injection vulnerability in adm_config_set.php in Mantis before 1.1.2 allows remote authenticated administrators to execute arbitrary co
OrtaCVSS 6,5Kavram kanıtıEPSS %9mantis · mantis27 Tem 2008
- CVE-2006-157728İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in view_all_set.php in Mantis 1.0.1, 1.0.0rc5, and earlier allow remote attackers to inj
OrtaCVSS 6,8İstismar yokEPSS %2mantis · mantis2 Nis 2006
- CVE-2005-333928İzleyin
Mantis before 0.19.3 caches the User ID longer than necessary, which has unknown impact and attack vectors.
YüksekCVSS 7,2İstismar yokEPSS %0mantis · mantis27 Eki 2005
- CVE-2008-468824İzleyin
core/string_api.php in Mantis before 1.1.3 does not check the privileges of the viewer before composing a link with issue data in the source
OrtaCVSS 5,0İstismar yokEPSS %12mantis · mantis22 Eki 2008
- CVE-2004-173121İzleyin
signup_page.php in Mantis bugtracker allows remote attackers to send e-mail bombs by creating multiple users and providing the same e-mail a
OrtaCVSS 5,0Kavram kanıtıEPSS %3mantis · mantis20 Ağu 2004
- CVE-2005-452121İzleyin
CRLF injection vulnerability in Mantis 1.0.0rc3 and earlier allows remote attackers to modify HTTP headers and conduct HTTP response splitti
OrtaCVSS 5,0İstismar yokEPSS %2mantis · mantis27 Ara 2005
- CVE-2005-452021İzleyin
Unspecified "port injection" vulnerabilities in filters in Mantis 1.0.0rc3 and earlier have unknown impact and attack vectors.
OrtaCVSS 5,0İstismar yokEPSS %2mantis · mantis27 Ara 2005
- CVE-2006-657421İzleyin
Mantis before 1.1.0a2 does not implement per-item access control for Issue History (Bug History), which allows remote attackers to obtain se
OrtaCVSS 5,0İstismar yokEPSS %2mantis · mantis15 Ara 2006