Cross-Site Scripting Vulnerabilities in Mantis Product by MantisBT
CVE-2006-1577

Currently unrated

Key Information:

Vendor

Mantis

Status
Vendor
CVE Published:
2 April 2006

What is CVE-2006-1577?

Multiple Cross-Site Scripting (XSS) vulnerabilities exist in Mantis, specifically in the view_all_set.php file. These vulnerabilities allow remote attackers to inject arbitrary web scripts or HTML using the parameters: start_day, start_year, and start_month. Successful exploitation could lead to unauthorized actions being performed on behalf of users or exposure of sensitive information within the affected application.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.