← Back

CVE-2006-0841

nvd nist
Published: Feb 22, 2006Modified: Apr 16, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Multiple cross-site scripting (XSS) vulnerabilities in Mantis 1.00rc4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) hide_status, (2) handler_id, (3) user_monitor, (4) reporter_id, (5) view_type, (6) show_severity, (7) show_category, (8) show_status, (9) show_resolution, (10) show_build, (11) show_profile, (12) show_priority, (13) highlight_changed, (14) relationship_type, and (15) relationship_bug parameters in (a) view_all_set.php; the (16) sort parameter in (b) manage_user_page.php; the (17) view_type parameter in (c) view_filters_page.php; and the (18) title parameter in (d) proj_doc_delete.php. NOTE: item 17 might be subsumed by CVE-2005-4522.

Affected (61)

Products: Mantis: Mantis
1 product
Mantis
Configuration A
61 vulnerable
Vulnerable SoftwareAffected Versions
Mantis
Version 0.10.0
Version 0.10.1
Version 0.10.2
Version 0.10
Version 0.11.0
Version 0.11.1
Version 0.11
Version 0.12.0
Version 0.12
Version 0.13.0
Version 0.13.1
Version 0.13
Version 0.14.0
Version 0.14.1
Version 0.14.2
Version 0.14.3
Version 0.14.4
Version 0.14.5
Version 0.14.6
Version 0.14.7
Version 0.14.8
Version 0.14
Version 0.15.0
Version 0.15.1
Version 0.15.2
Version 0.15
Version 0.16.0
Version 0.16
Version 0.17.0
Version 0.17.4a
Version 0.17
Version 0.18.0
Version 0.18.0_rc1
Version 0.18.0a1
Version 0.18.0a2
Version 0.18.0a3
Version 0.18.0a4
Version 0.18.1
Version 0.18.2
Version 0.18.3
Version 0.18
Version 0.18a1
Version 0.19.0
Version 0.19.0_rc1
Version 0.19.0a1
Version 0.19.0a2
Version 0.19.0a
Version 0.19.1
Version 0.19.2
Version 0.19.3
Version 0.19.4
Version 0.9.0
Version 0.9.1
Version 0.9
Version 1.0.0_rc1
Version 1.0.0_rc2
Version 1.0.0_rc3
Version 1.0.0_rc4
Version 1.0.0a1
Version 1.0.0a2
Version 1.0.0a3

References (18)

Source: cve@mitre.org
ExploitPatchVendor Advisory
Source: cve@mitre.org
Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.