Cross-Site Scripting Vulnerabilities in Mantis by Mantishub
CVE-2006-0841
Currently unrated
What is CVE-2006-0841?
Multiple cross-site scripting vulnerabilities in Mantis 1.00rc4 and earlier enable remote attackers to inject arbitrary web scripts or HTML through various parameters in key PHP files. These exploitable parameters include hide_status, handler_id, and user_monitor, amongst others, found in view_all_set.php, manage_user_page.php, view_filters_page.php, and proj_doc_delete.php. Successful exploitation can lead to unauthorized access or manipulation of user sessions.
