← Back

CVE-2006-0840

nvd nist
Published: Feb 22, 2006Modified: Apr 16, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:N/A:P
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

manage_user_page.php in Mantis 1.00rc4 and earlier does not properly handle a sort parameter containing a ' (quote) character, which allows remote attackers to trigger a SQL error that may be repeatedly reported to a user who makes subsequent web accesses with the MANTIS_MANAGE_COOKIE cookie. NOTE: this issue might be the same as vector 2 in CVE-2005-4519.

Affected (61)

Products: Mantis: Mantis
1 product
Mantis
Configuration A
61 vulnerable
Vulnerable SoftwareAffected Versions
Mantis
Up to 1.0.0_rc4
Version 0.10.0
Version 0.10.1
Version 0.10.2
Version 0.10
Version 0.11.0
Version 0.11.1
Version 0.11
Version 0.12.0
Version 0.12
Version 0.13.0
Version 0.13.1
Version 0.13
Version 0.14.0
Version 0.14.1
Version 0.14.2
Version 0.14.3
Version 0.14.4
Version 0.14.5
Version 0.14.6
Version 0.14.7
Version 0.14.8
Version 0.14
Version 0.15.0
Version 0.15.1
Version 0.15.2
Version 0.15
Version 0.16.0
Version 0.16
Version 0.17.0
Version 0.17.4a
Version 0.17
Version 0.18.0
Version 0.18.0_rc1
Version 0.18.0a1
Version 0.18.0a2
Version 0.18.0a3
Version 0.18.0a4
Version 0.18.1
Version 0.18.2
Version 0.18.3
Version 0.18
Version 0.18a1
Version 0.19.0
Version 0.19.0_rc1
Version 0.19.0a1
Version 0.19.0a2
Version 0.19.0a
Version 0.19.1
Version 0.19.2
Version 0.19.3
Version 0.19.4
Version 0.9.0
Version 0.9.1
Version 0.9
Version 1.0.0_rc1
Version 1.0.0_rc2
Version 1.0.0_rc3
Version 1.0.0a1
Version 1.0.0a2
Version 1.0.0a3

Timeline

No history available yet.