Metrics
Metrics |
Score |
Severity |
CVSS Vector |
Source |
V2 |
4.3 |
|
AV:N/AC:M/Au:N/C:N/I:P/A:N |
[email protected] |
EPSS
EPSS is a scoring model that predicts the likelihood of a vulnerability being exploited.
EPSS Score
The EPSS model produces a probability score between 0 and 1 (0 and 100%). The higher the score, the greater the probability that a vulnerability will be exploited.
EPSS Percentile
The percentile is used to rank CVE according to their EPSS score. For example, a CVE in the 95th percentile according to its EPSS score is more likely to be exploited than 95% of other CVE. Thus, the percentile is used to compare the EPSS score of a CVE with that of other CVE.
Exploit information
Exploit Database EDB-ID : 26172
Publication date : 2005-08-18 22h00 +00:00
Author : anonymous
EDB Verified : Yes
source: https://www.securityfocus.com/bid/14604/info
Mantis is prone to multiple input validation vulnerabilities. These issues involve cross-site scripting, HTML injection and variable poisoning, and are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage the cross-site scripting issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
Successful exploitation of the HTML injection issue could result in having attacker-supplied HTML and script code executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.
The variable poisoning issue could result in unauthorized access and denial of service attacks.
A - Cross Site Scripting Vulnerabilities
http://www.example.com/view_all_set.php?sort=severity&dir="><script>alert(document.cookie)</script>&type=2
B.- Database scanner via variable poisoning
http://www.example.com/core/database_api.php?g_db_type=mysql://invaliduser@localhost:3336
http://www.example.com/core/database_api.php?g_db_type=mysql://root@localhost:3336
http://www.example.com/core/database_api.php?g_db_type=informix://localhost:8080
http://www.example.com/core/database_api.php?g_db_type=mysql://
[email protected]
Products Mentioned
Configuraton 0
Mantis>>Mantis >> Version 0.19.0
Mantis>>Mantis >> Version 0.19.0_rc1
Mantis>>Mantis >> Version 0.19.0a1
Mantis>>Mantis >> Version 0.19.0a2
Mantis>>Mantis >> Version 0.19.1
Mantis>>Mantis >> Version 0.19.2
Mantis>>Mantis >> Version 1.0.0a1
Mantis>>Mantis >> Version 1.0.0a2
Mantis>>Mantis >> Version 1.0.0a3
Configuraton 0
Debian>>Debian_linux >> Version 3.1
Debian>>Debian_linux >> Version 3.1
Debian>>Debian_linux >> Version 3.1
Debian>>Debian_linux >> Version 3.1
Debian>>Debian_linux >> Version 3.1
Debian>>Debian_linux >> Version 3.1
Debian>>Debian_linux >> Version 3.1
Debian>>Debian_linux >> Version 3.1
Debian>>Debian_linux >> Version 3.1
Debian>>Debian_linux >> Version 3.1
Debian>>Debian_linux >> Version 3.1
Debian>>Debian_linux >> Version 3.1
Debian>>Debian_linux >> Version 3.1
Gentoo>>Linux >> Version *
References