CVE |
Vendors |
Products |
Updated |
CVSS |
CVE-2019-15715 |
1 Mantisbt |
1 Mantisbt |
2019-10-16 |
6.5 |
MantisBT before 1.3.20 and 2.22.1 allows Post Authentication Command Injection, leading to Remote Code Execution. |
CVE-2019-15074 |
1 Mantisbt |
1 Mantisbt |
2019-09-04 |
6.8 |
The Timeline feature in my_view_page.php in MantisBT through 2.21.1 has a stored cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code (if CSP settings permit it) after uploading an attachment with a crafted filename. The... |
CVE-2018-16514 |
1 Mantisbt |
1 Mantisbt |
2019-06-21 |
2.6 |
A cross-site scripting (XSS) vulnerability in the View Filters page (view_filters_page.php) and Edit Filter page (manage_filter_edit_page.php) in MantisBT 2.1.0 through 2.17.0 allows remote attackers to inject arbitrary code (if CSP settings... |
CVE-2018-9839 |
1 Mantisbt |
1 Mantisbt |
2019-06-09 |
4.0 |
An issue was discovered in MantisBT through 1.3.14, and 2.0.0. Using a crafted request on bug_report_page.php (modifying the 'm_id' parameter), any user with REPORTER access or above is able to view any private issue's details (summary,... |
CVE-2017-6799 |
1 Mantisbt |
1 Mantisbt |
2019-03-19 |
4.3 |
A cross-site scripting (XSS) vulnerability in view_filters_page.php in MantisBT before 2.2.1 allows remote attackers to inject arbitrary JavaScript via the 'view_type' parameter. |
CVE-2017-6797 |
1 Mantisbt |
1 Mantisbt |
2019-03-19 |
4.3 |
A cross-site scripting (XSS) vulnerability in bug_change_status_page.php in MantisBT before 1.3.7 and 2.x before 2.2.1 allows remote attackers to inject arbitrary JavaScript via the 'action_type' parameter. |
CVE-2018-6382 |
1 Mantisbt |
1 Mantisbt |
2019-03-04 |
2.1 |
** DISPUTED ** MantisBT 2.10.0 allows local users to conduct SQL Injection attacks via the vendor/adodb/adodb-php/server.php sql parameter in a request to the 127.0.0.1 IP address. NOTE: the vendor disputes the significance of this report because... |
CVE-2018-17782 |
1 Mantisbt |
1 Mantisbt |
2018-12-07 |
3.5 |
A cross-site scripting (XSS) vulnerability in the Manage Filters page (manage_filter_page.php) in MantisBT 2.1.0 through 2.17.1 allows remote attackers (if access rights permit it) to inject arbitrary code (if CSP settings permit it) through a... |
CVE-2018-17783 |
1 Mantisbt |
1 Mantisbt |
2018-12-07 |
3.5 |
A cross-site scripting (XSS) vulnerability in the Edit Filter page (manage_filter_edit page.php) in MantisBT 2.1.0 through 2.17.1 allows remote attackers (if access rights permit it) to inject arbitrary code (if CSP settings permit it) through a... |
CVE-2008-3102 |
1 Mantisbt |
1 Mantisbt |
2018-10-11 |
5.0 |
Mantis 1.1.x through 1.1.2 and 1.2.x through 1.2.0a2 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie. |
CVE-2010-2574 |
1 Mantisbt |
1 Mantisbt |
2018-10-10 |
2.1 |
Cross-site scripting (XSS) vulnerability in manage_proj_cat_add.php in MantisBT 1.2.2 allows remote authenticated administrators to inject arbitrary web script or HTML via the name parameter in an Add Category action. |
CVE-2011-3578 |
1 Mantisbt |
1 Mantisbt |
2018-10-09 |
4.3 |
Cross-site scripting (XSS) vulnerability in bug_actiongroup_ext_page.php in MantisBT before 1.2.8 allows remote attackers to inject arbitrary web script or HTML via the action parameter, related to bug_actiongroup_page.php, a different... |
CVE-2011-3358 |
1 Mantisbt |
1 Mantisbt |
2018-10-09 |
4.3 |
Multiple cross-site scripting (XSS) vulnerabilities in MantisBT before 1.2.8 allow remote attackers to inject arbitrary web script or HTML via the (1) os, (2) os_build, or (3) platform parameter to (a) bug_report_page.php or (b)... |
CVE-2011-3357 |
1 Mantisbt |
1 Mantisbt |
2018-10-09 |
6.8 |
Directory traversal vulnerability in bug_actiongroup_ext_page.php in MantisBT before 1.2.8 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the action parameter, related to bug_actiongroup_page.php. |
CVE-2011-3356 |
1 Mantisbt |
1 Mantisbt |
2018-10-09 |
4.3 |
Multiple cross-site scripting (XSS) vulnerabilities in config_defaults_inc.php in MantisBT before 1.2.8 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO, as demonstrated by the PATH_INFO to (1)... |
CVE-2018-13055 |
1 Mantisbt |
1 Mantisbt |
2018-10-04 |
4.3 |
A cross-site scripting (XSS) vulnerability in the View Filters page (view_filters_page.php) in MantisBT 2.1.0 through 2.15.0 allows remote attackers to inject arbitrary code (if CSP settings permit it) through a crafted PATH_INFO. |
CVE-2018-14504 |
1 Mantisbt |
1 Mantisbt |
2018-10-02 |
4.3 |
An issue was discovered in manage_filter_edit_page.php in MantisBT 2.x through 2.15.0. A cross-site scripting (XSS) vulnerability in the Edit Filter page allows execution of arbitrary code (if CSP settings permit it) when displaying a filter with... |
CVE-2018-6526 |
1 Mantisbt |
1 Mantisbt |
2018-04-08 |
5.0 |
view_all_bug_page.php in MantisBT 2.10.0-development before 2018-02-02 allows remote attackers to discover the full path via an invalid filter parameter, related to a filter_ensure_valid_filter call in current_user_api.php. |
CVE-2014-9624 |
1 Mantisbt |
1 Mantisbt |
2017-09-20 |
5.0 |
CAPTCHA bypass vulnerability in MantisBT before 1.2.19. |
CVE-2014-9573 |
1 Mantisbt |
1 Mantisbt |
2017-09-08 |
6.0 |
SQL injection vulnerability in manage_user_page.php in MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 allows remote administrators with FILE privileges to execute arbitrary SQL commands via the MANTIS_MANAGE_USERS_COOKIE cookie. |