This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Mantis First view 2005-08-24
Product Mantis Last view 2008-10-22
Version 1.0.0a3 Type Application
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:mantis:mantis

Activity : Overall

Related : CVE

  Date Alert Description
7.5 2008-10-22 CVE-2008-4689

Mantis before 1.1.3 does not unset the session cookie during logout, which makes it easier for remote attackers to hijack sessions.

5 2008-10-22 CVE-2008-4688

core/string_api.php in Mantis before 1.1.3 does not check the privileges of the viewer before composing a link with issue data in the source anchor, which allows remote attackers to discover an issue's title and status via a request with a modified issue number.

9 2008-10-22 CVE-2008-4687

manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort parameter containing PHP sequences, which are processed by create_function within the multi_sort function in core/utility_api.php.

7.5 2008-07-27 CVE-2008-3333

Directory traversal vulnerability in core/lang_api.php in Mantis before 1.1.2 allows remote attackers to include and execute arbitrary files via the language parameter to the user preferences page (account_prefs_update.php).

6.5 2008-07-27 CVE-2008-3332

Eval injection vulnerability in adm_config_set.php in Mantis before 1.1.2 allows remote authenticated administrators to execute arbitrary code via the value parameter.

3.5 2008-07-27 CVE-2008-3331

Cross-site scripting (XSS) vulnerability in return_dynamic_filters.php in Mantis before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the filter_target parameter.

4.3 2008-01-23 CVE-2008-0404

Cross-site scripting (XSS) vulnerability in Mantis before 1.1.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to the "Most active bugs" summary.

4.3 2008-01-03 CVE-2007-6611

Cross-site scripting (XSS) vulnerability in view.php in Mantis before 1.1.0 allows remote attackers to inject arbitrary web script or HTML via a filename, related to bug_report.php.

5 2006-12-15 CVE-2006-6574

Mantis before 1.1.0a2 does not implement per-item access control for Issue History (Bug History), which allows remote attackers to obtain sensitive information by reading the Change column, as demonstrated by the Change column of a custom field.

10 2006-12-13 CVE-2006-6515

Mantis before 1.1.0a2 sets the default value of $g_bug_reminder_threshold to "reporter" instead of a more privileged role, which has unknown impact and attack vectors, possibly related to frequency of reminders.

6.8 2006-04-02 CVE-2006-1577

Multiple cross-site scripting (XSS) vulnerabilities in view_all_set.php in Mantis 1.0.1, 1.0.0rc5, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) start_day, (2) start_year, and (3) start_month parameters.

4.3 2006-02-21 CVE-2006-0841

Multiple cross-site scripting (XSS) vulnerabilities in Mantis 1.00rc4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) hide_status, (2) handler_id, (3) user_monitor, (4) reporter_id, (5) view_type, (6) show_severity, (7) show_category, (8) show_status, (9) show_resolution, (10) show_build, (11) show_profile, (12) show_priority, (13) highlight_changed, (14) relationship_type, and (15) relationship_bug parameters in (a) view_all_set.php; the (16) sort parameter in (b) manage_user_page.php; the (17) view_type parameter in (c) view_filters_page.php; and the (18) title parameter in (d) proj_doc_delete.php. NOTE: item 17 might be subsumed by CVE-2005-4522.

5 2006-02-21 CVE-2006-0840

manage_user_page.php in Mantis 1.00rc4 and earlier does not properly handle a sort parameter containing a ' (quote) character, which allows remote attackers to trigger a SQL error that may be repeatedly reported to a user who makes subsequent web accesses with the MANTIS_MANAGE_COOKIE cookie. NOTE: this issue might be the same as vector 2 in CVE-2005-4519.

10 2006-02-13 CVE-2006-0665

Unspecified vulnerability in (1) query_store.php and (2) manage_proj_create.php in Mantis before 1.0.0 has unknown impact and attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. An original vendor bug report is referenced, but not accessible to the general public.

4.3 2006-02-13 CVE-2006-0664

Cross-site scripting (XSS) vulnerability in config_defaults_inc.php in Mantis before 1.0 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. An original vendor bug report is referenced, but not accessible to the general public.

5 2005-12-27 CVE-2005-4523

Mantis 1.0.0rc3 and earlier discloses private bugs via public RSS feeds, which allows remote attackers to obtain sensitive information.

4.3 2005-12-27 CVE-2005-4522

Multiple cross-site scripting (XSS) vulnerabilities in the view_filters_page.php filters script in Mantis 1.0.0rc3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) view_type and (2) target_field parameters.

5 2005-12-27 CVE-2005-4520

Unspecified "port injection" vulnerabilities in filters in Mantis 1.0.0rc3 and earlier have unknown impact and attack vectors. NOTE: due to a lack of relevant details in the vendor changelog, which is the source of this description, it is unclear whether this is a duplicate of another CVE.

7.5 2005-12-27 CVE-2005-4519

Multiple SQL injection vulnerabilities in the manage user page (manage_user_page.php) in Mantis 1.0.0rc3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) prefix and (2) sort parameters to the manage user page (manage_user_page.php), or (3) the sort parameter to view_all_set.php.

4.3 2005-12-14 CVE-2005-4238

Cross-site scripting (XSS) vulnerability in view_filters_page.php in Mantis 1.0.0rc3 and earlier allows remote attackers to inject arbitrary web script or HTML via the target_field parameter.

4.3 2005-09-28 CVE-2005-3091

Cross-site scripting (XSS) vulnerability in Mantis before 1.0.0rc1 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors, as identified by bug#0005751 "thraxisp".

4.3 2005-09-28 CVE-2005-3090

Cross-site scripting (XSS) vulnerability in bug_actiongroup_page.php in Mantis 0.19.0a1 through 1.0.0a3 allows remote attackers to inject arbitrary web script or HTML via the summary of the bug, which is not quoted when view_all_bug_page.php is used to delete the bug, as identified by bug#0006002, a different vulnerability than CVE-2005-2557.

4.3 2005-09-28 CVE-2005-2557

Cross-site scripting (XSS) vulnerability in view_all_set.php in Mantis 0.19.0a1 through 1.0.0a3 allows remote attackers to inject arbitrary web script or HTML via the dir parameter, as identified by bug#0005959, and a different vulnerability than CVE-2005-3090.

7.5 2005-08-24 CVE-2005-2556

core/database_api.php in Mantis 0.19.0a1 through 1.0.0a3, with register_globals enabled, allows remote attackers to connect to internal databases by modifying the g_db_type variable and monitoring the speed of responses, as identified by bug#0005956.

CWE : Common Weakness Enumeration

%idName
37% (3) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')
25% (2) CWE-94 Failure to Control Generation of Code ('Code Injection')
12% (1) CWE-287 Improper Authentication
12% (1) CWE-200 Information Exposure
12% (1) CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path ...

Open Source Vulnerability Database (OSVDB)

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
id Description
49478 Mantis Cookie Session Hijacking
49477 Mantis core/string_api.php Modified Issue Number Remote Information Disclosure
49157 Mantis manage_proj_page.php sort Parameter Arbitrary PHP Code Execution
47854 Mantis adm_config_set.php value Variable Arbitrary Remote Code Execution
47176 Mantis return_dynamic_filters.php filter_target Parameter XSS
47175 Mantis account_prefs_update.php language Parameter Traversal Local File Inclu...
40530 Mantis Most Active Bugs Summary Page XSS
39873 Mantis view.php Filename XSS
37108 Mantis $g_bug_reminder_threshold Reporter Privilege Escalation
32195 Mantis Issue History Custom Field Information Disclosure
28626 Mantis manage_user_page.php sort Parameter SQL Injection DoS
24292 Mantis view_all_set.php Multiple Parameter XSS
23248 Mantis view_all_set.php Multiple Parameter XSS
23082 Mantis manage_proj_create.php title Parameter XSS
23081 Mantis query_store.php Unspecified Input Validation Issue
23080 Mantis config_defaults_inc.php Unspecified XSS
22487 Mantis manage_user_page.php sort Parameter XSS
22341 Mantis Filter Port Unspecified XSS
22057 Mantis Public RSS Feed Private Bug Disclosure
22053 Mantis view_filters_page.php Multiple Parameter XSS
22052 Mantis view_all_set.php sort Parameter SQL Injection
22051 Mantis manage_user_page.php Multiple Parameter SQL Injection
21686 Mantis view_filters_page.php target_field Parameter XSS
18903 Mantis Unspecified SQL Injection
18901 Mantis view_all_set.php dir Parameter XSS

OpenVAS Exploits

id Description
2009-02-17 Name : Fedora Update for mantis FEDORA-2008-0282
File : nvt/gb_fedora_2008_0282_mantis_fc7.nasl
2009-02-17 Name : Fedora Update for mantis FEDORA-2008-0353
File : nvt/gb_fedora_2008_0353_mantis_fc8.nasl
2009-02-17 Name : Fedora Update for mantis FEDORA-2008-0796
File : nvt/gb_fedora_2008_0796_mantis_fc7.nasl
2009-02-17 Name : Fedora Update for mantis FEDORA-2008-0856
File : nvt/gb_fedora_2008_0856_mantis_fc8.nasl
2008-12-10 Name : FreeBSD Ports: mantis
File : nvt/freebsd_mantis3.nasl
2008-12-10 Name : FreeBSD Ports: mantis
File : nvt/freebsd_mantis4.nasl
2008-12-03 Name : Gentoo Security Advisory GLSA 200812-07 (mantisbt)
File : nvt/glsa_200812_07.nasl
2008-09-24 Name : Gentoo Security Advisory GLSA 200809-10 (mantisbt)
File : nvt/glsa_200809_10.nasl
2008-09-24 Name : Gentoo Security Advisory GLSA 200803-04 (mantis)
File : nvt/glsa_200803_04.nasl
2008-09-24 Name : Gentoo Security Advisory GLSA 200512-12 (Mantis)
File : nvt/glsa_200512_12.nasl
2008-09-24 Name : Gentoo Security Advisory GLSA 200509-16 (Mantis)
File : nvt/glsa_200509_16.nasl
2008-09-04 Name : FreeBSD Ports: mantis
File : nvt/freebsd_mantis0.nasl
2008-09-04 Name : FreeBSD Ports: mantis
File : nvt/freebsd_mantis1.nasl
2008-01-31 Name : Debian Security Advisory DSA 1467-1 (mantis)
File : nvt/deb_1467_1.nasl
2008-01-17 Name : Debian Security Advisory DSA 944-1 (mantis)
File : nvt/deb_944_1.nasl
2008-01-17 Name : Debian Security Advisory DSA 905-1 (mantis)
File : nvt/deb_905_1.nasl
2008-01-17 Name : Debian Security Advisory DSA 778-1 (mantis)
File : nvt/deb_778_1.nasl
2008-01-17 Name : Debian Security Advisory DSA 1133-1 (mantis)
File : nvt/deb_1133_1.nasl
2006-03-26 Name : Mantis Multiple Flaws (4)
File : nvt/mantis_multiple_vulns4.nasl

Nessus® Vulnerability Scanner

id Description
2008-12-08 Name: The remote FreeBSD host is missing a security-related update.
File: freebsd_pkg_29255141c3df11dda7210030843d3802.nasl - Type: ACT_GATHER_INFO
2008-12-08 Name: The remote FreeBSD host is missing a security-related update.
File: freebsd_pkg_af2745c0c3e011dda7210030843d3802.nasl - Type: ACT_GATHER_INFO
2008-12-03 Name: The remote Gentoo host is missing one or more security-related patches.
File: gentoo_GLSA-200812-07.nasl - Type: ACT_GATHER_INFO
2008-09-22 Name: The remote Gentoo host is missing one or more security-related patches.
File: gentoo_GLSA-200809-10.nasl - Type: ACT_GATHER_INFO
2008-03-07 Name: The remote Gentoo host is missing one or more security-related patches.
File: gentoo_GLSA-200803-04.nasl - Type: ACT_GATHER_INFO
2008-01-27 Name: The remote Fedora host is missing a security update.
File: fedora_2008-0796.nasl - Type: ACT_GATHER_INFO
2008-01-27 Name: The remote Fedora host is missing a security update.
File: fedora_2008-0856.nasl - Type: ACT_GATHER_INFO
2008-01-21 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-1467.nasl - Type: ACT_GATHER_INFO
2008-01-07 Name: The remote Fedora host is missing a security update.
File: fedora_2008-0282.nasl - Type: ACT_GATHER_INFO
2008-01-07 Name: The remote Fedora host is missing a security update.
File: fedora_2008-0353.nasl - Type: ACT_GATHER_INFO
2006-10-14 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-905.nasl - Type: ACT_GATHER_INFO
2006-10-14 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-944.nasl - Type: ACT_GATHER_INFO
2006-10-14 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-1133.nasl - Type: ACT_GATHER_INFO
2006-05-13 Name: The remote FreeBSD host is missing a security-related update.
File: freebsd_pkg_592815da9eed11dab410000e0c2e438a.nasl - Type: ACT_GATHER_INFO
2006-05-13 Name: The remote FreeBSD host is missing a security-related update.
File: freebsd_pkg_6e3b12e26ce311dab90c000e0c2e438a.nasl - Type: ACT_GATHER_INFO
2005-12-30 Name: The remote Gentoo host is missing one or more security-related patches.
File: gentoo_GLSA-200512-12.nasl - Type: ACT_GATHER_INFO
2005-10-27 Name: The remote web server contains a PHP application that is affected by multiple...
File: mantis_file_incl_sql_inject.nasl - Type: ACT_GATHER_INFO
2005-10-05 Name: The remote Gentoo host is missing one or more security-related patches.
File: gentoo_GLSA-200509-16.nasl - Type: ACT_GATHER_INFO
2005-08-23 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-778.nasl - Type: ACT_GATHER_INFO
2005-08-22 Name: The remote web server contains a PHP application that is affected by several ...
File: mantis_multiple_vulns4.nasl - Type: ACT_ATTACK