Cross-site Scripting Vulnerability in Mantis Bug Tracker by Mantis Bug Tracker Team
CVE-2006-0664

Currently unrated

Key Information:

Vendor

Mantis

Status
Vendor
CVE Published:
13 February 2006

What is CVE-2006-0664?

A vulnerability exists in the config_defaults_inc.php file of Mantis which allows remote attackers to execute arbitrary web scripts or HTML. This is executed through various attack vectors that are currently not well-defined. The lack of clarity surrounding the specifics of this vulnerability increases the urgency for users of Mantis to apply critical patches and to adhere to best practices for securing their web applications.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.