Vulnerabilities
Vulnerable Software
Mantisbt:  >> Mantisbt  >> 1.2.15  Security Vulnerabilities
SQL injection vulnerability in the mci_file_get function in api/soap/mc_file_api.php in MantisBT before 1.2.16 allows remote attackers to execute arbitrary SQL commands via a crafted envelope tag in a mc_issue_attachment_get SOAP request.
CVSS Score
7.5
EPSS Score
0.006
Published
2014-03-18
SQL injection vulnerability in the manage configuration page (adm_config_report.php) in MantisBT 1.2.13 through 1.2.16 allows remote authenticated administrators to execute arbitrary SQL commands via the filter_config_id parameter.
CVSS Score
6.5
EPSS Score
0.454
Published
2014-03-05
Cross-site scripting (XSS) vulnerability in account_sponsor_page.php in MantisBT 1.0.0 through 1.2.15 allows remote authenticated users to inject arbitrary web script or HTML via a project name.
CVSS Score
3.5
EPSS Score
0.002
Published
2014-01-10


Contact Us

Shodan ® - All rights reserved