4.3

CVE-2006-0841

Exploit

Multiple cross-site scripting (XSS) vulnerabilities in Mantis 1.00rc4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) hide_status, (2) handler_id, (3) user_monitor, (4) reporter_id, (5) view_type, (6) show_severity, (7) show_category, (8) show_status, (9) show_resolution, (10) show_build, (11) show_profile, (12) show_priority, (13) highlight_changed, (14) relationship_type, and (15) relationship_bug parameters in (a) view_all_set.php; the (16) sort parameter in (b) manage_user_page.php; the (17) view_type parameter in (c) view_filters_page.php; and the (18) title parameter in (d) proj_doc_delete.php.  NOTE: item 17 might be subsumed by CVE-2005-4522.

Data is provided by the National Vulnerability Database (NVD)
MantisMantis Version0.9
MantisMantis Version0.9.0
MantisMantis Version0.9.1
MantisMantis Version0.10
MantisMantis Version0.10.0
MantisMantis Version0.10.1
MantisMantis Version0.10.2
MantisMantis Version0.11
MantisMantis Version0.11.0
MantisMantis Version0.11.1
MantisMantis Version0.12
MantisMantis Version0.12.0
MantisMantis Version0.13
MantisMantis Version0.13.0
MantisMantis Version0.13.1
MantisMantis Version0.14
MantisMantis Version0.14.0
MantisMantis Version0.14.1
MantisMantis Version0.14.2
MantisMantis Version0.14.3
MantisMantis Version0.14.4
MantisMantis Version0.14.5
MantisMantis Version0.14.6
MantisMantis Version0.14.7
MantisMantis Version0.14.8
MantisMantis Version0.15
MantisMantis Version0.15.0
MantisMantis Version0.15.1
MantisMantis Version0.15.2
MantisMantis Version0.16
MantisMantis Version0.16.0
MantisMantis Version0.17
MantisMantis Version0.17.0
MantisMantis Version0.17.4a
MantisMantis Version0.18
MantisMantis Version0.18.0
MantisMantis Version0.18.0_rc1
MantisMantis Version0.18.0a1
MantisMantis Version0.18.0a2
MantisMantis Version0.18.0a3
MantisMantis Version0.18.0a4
MantisMantis Version0.18.1
MantisMantis Version0.18.2
MantisMantis Version0.18.3
MantisMantis Version0.18a1
MantisMantis Version0.19.0
MantisMantis Version0.19.0_rc1
MantisMantis Version0.19.0a
MantisMantis Version0.19.0a1
MantisMantis Version0.19.0a2
MantisMantis Version0.19.1
MantisMantis Version0.19.2
MantisMantis Version0.19.3
MantisMantis Version0.19.4
MantisMantis Version1.0.0_rc1
MantisMantis Version1.0.0_rc2
MantisMantis Version1.0.0_rc3
MantisMantis Version1.0.0_rc4
MantisMantis Version1.0.0a1
MantisMantis Version1.0.0a2
MantisMantis Version1.0.0a3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 10.75% 0.93
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N