İçeriğe atla
Noroxi

mantis kayıtları

mantis üreticisine ait 46 yayımlanmış kayıt.

Tüm kayıtlar

46 kayıt
  • CVE-2008-4687
    56Planlayın

    manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort parameter containing PHP

    KritikCVSS 9,0SilahlaştırılmışEPSS %67

    mantis · mantis22 Eki 2008

  • CVE-2002-1110
    41Planlayın

    Multiple SQL injection vulnerabilities in Mantis 0.17.2 and earlier, when running without magic_quotes_gpc enabled, allows remote attackers

    KritikCVSS 10,0İstismar yokEPSS %2

    mantis · mantis4 Eki 2002

  • CVE-2006-0665
    41Planlayın

    Unspecified vulnerability in (1) query_store.php and (2) manage_proj_create.php in Mantis before 1.0.0 has unknown impact and attack vectors

    KritikCVSS 10,0İstismar yokEPSS %2

    mantis · mantis13 Şub 2006

  • CVE-2006-6515
    40Planlayın

    Mantis before 1.1.0a2 sets the default value of $g_bug_reminder_threshold to "reporter" instead of a more privileged role, which has unknown

    KritikCVSS 10,0İstismar yokEPSS %1

    mantis · mantis13 Ara 2006

  • CVE-2006-0146
    34İzleyin

    The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Ca

    YüksekCVSS 7,5Kavram kanıtıEPSS %13

    mantis · mantis9 Oca 2006

  • CVE-2006-0147
    34İzleyin

    Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (

    YüksekCVSS 7,5Kavram kanıtıEPSS %13

    john lim · adodb9 Oca 2006

  • CVE-2005-3335
    32İzleyin

    PHP file inclusion vulnerability in bug_sponsorship_list_view_inc.php in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbit

    YüksekCVSS 7,5İstismar yokEPSS %7

    mantis · mantis27 Eki 2005

  • CVE-2005-4518
    31İzleyin

    Mantis before 0.19.4 allows remote attackers to bypass the file upload size restriction by modifying the max_file_size parameter to (1) bug_

    YüksekCVSS 7,5İstismar yokEPSS %4

    mantis · mantis27 Ara 2005

  • CVE-2002-1113
    31İzleyin

    summary_graph_functions.php in Mantis 0.17.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the g_jpgraph_pa

    YüksekCVSS 7,5Kavram kanıtıEPSS %3

    mantis · mantis4 Eki 2002

  • CVE-2002-1114
    31İzleyin

    config_inc2.php in Mantis before 0.17.4 allows remote attackers to execute arbitrary code or read arbitrary files via the parameters (1) g_b

    YüksekCVSS 7,5İstismar yokEPSS %3

    mantis · mantis4 Eki 2002

  • CVE-2008-4689
    31İzleyin

    Mantis before 1.1.3 does not unset the session cookie during logout, which makes it easier for remote attackers to hijack sessions.

    YüksekCVSS 7,5İstismar yokEPSS %2

    mantis · mantis22 Eki 2008

  • CVE-2008-3333
    31İzleyin

    Directory traversal vulnerability in core/lang_api.php in Mantis before 1.1.2 allows remote attackers to include and execute arbitrary files

    YüksekCVSS 7,5İstismar yokEPSS %2

    mantis · mantis27 Tem 2008

  • CVE-2005-4519
    31İzleyin

    Multiple SQL injection vulnerabilities in the manage user page (manage_user_page.php) in Mantis 1.0.0rc3 and earlier allow remote attackers

    YüksekCVSS 7,5İstismar yokEPSS %2

    mantis · mantis27 Ara 2005

  • CVE-2005-3336
    31İzleyin

    SQL injection vulnerability in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

    YüksekCVSS 7,5İstismar yokEPSS %2

    mantis · mantis27 Eki 2005

  • CVE-2004-1734
    31İzleyin

    PHP remote file inclusion vulnerability in Mantis 0.19.0a allows remote attackers to execute arbitrary PHP code by modifying the (1) t_core_

    YüksekCVSS 7,5İstismar yokEPSS %2

    mantis · mantis31 Ara 2004

  • CVE-2005-2556
    30İzleyin

    core/database_api.php in Mantis 0.19.0a1 through 1.0.0a3, with register_globals enabled, allows remote attackers to connect to internal data

    YüksekCVSS 7,5İstismar yokEPSS %2

    mantis · mantis24 Ağu 2005

  • CVE-2002-1116
    30İzleyin

    The "View Bugs" page (view_all_bug_page.php) in Mantis 0.17.4a and earlier includes summaries of private bugs for users that do not have acc

    YüksekCVSS 7,5İstismar yokEPSS %1

    mantis · mantis4 Eki 2002

  • CVE-2008-3332
    29İzleyin

    Eval injection vulnerability in adm_config_set.php in Mantis before 1.1.2 allows remote authenticated administrators to execute arbitrary co

    OrtaCVSS 6,5Kavram kanıtıEPSS %9

    mantis · mantis27 Tem 2008

  • CVE-2006-1577
    28İzleyin

    Multiple cross-site scripting (XSS) vulnerabilities in view_all_set.php in Mantis 1.0.1, 1.0.0rc5, and earlier allow remote attackers to inj

    OrtaCVSS 6,8İstismar yokEPSS %2

    mantis · mantis2 Nis 2006

  • CVE-2005-3339
    28İzleyin

    Mantis before 0.19.3 caches the User ID longer than necessary, which has unknown impact and attack vectors.

    YüksekCVSS 7,2İstismar yokEPSS %0

    mantis · mantis27 Eki 2005

  • CVE-2008-4688
    24İzleyin

    core/string_api.php in Mantis before 1.1.3 does not check the privileges of the viewer before composing a link with issue data in the source

    OrtaCVSS 5,0İstismar yokEPSS %12

    mantis · mantis22 Eki 2008

  • CVE-2004-1731
    21İzleyin

    signup_page.php in Mantis bugtracker allows remote attackers to send e-mail bombs by creating multiple users and providing the same e-mail a

    OrtaCVSS 5,0Kavram kanıtıEPSS %3

    mantis · mantis20 Ağu 2004

  • CVE-2005-4521
    21İzleyin

    CRLF injection vulnerability in Mantis 1.0.0rc3 and earlier allows remote attackers to modify HTTP headers and conduct HTTP response splitti

    OrtaCVSS 5,0İstismar yokEPSS %2

    mantis · mantis27 Ara 2005

  • CVE-2005-4520
    21İzleyin

    Unspecified "port injection" vulnerabilities in filters in Mantis 1.0.0rc3 and earlier have unknown impact and attack vectors.

    OrtaCVSS 5,0İstismar yokEPSS %2

    mantis · mantis27 Ara 2005

  • CVE-2006-6574
    21İzleyin

    Mantis before 1.1.0a2 does not implement per-item access control for Issue History (Bug History), which allows remote attackers to obtain se

    OrtaCVSS 5,0İstismar yokEPSS %2

    mantis · mantis15 Ara 2006