CVE Vulnerabilities

CVE-2006-0840

Published: Feb 22, 2006 | Modified: Oct 18, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

manage_user_page.php in Mantis 1.00rc4 and earlier does not properly handle a sort parameter containing a (quote) character, which allows remote attackers to trigger a SQL error that may be repeatedly reported to a user who makes subsequent web accesses with the MANTIS_MANAGE_COOKIE cookie. NOTE: this issue might be the same as vector 2 in CVE-2005-4519.

Affected Software

Name Vendor Start Version End Version
Mantis Mantis * 1.0.0_rc4 (including)
Mantis Mantis 0.9 (including) 0.9 (including)
Mantis Mantis 0.9.0 (including) 0.9.0 (including)
Mantis Mantis 0.9.1 (including) 0.9.1 (including)
Mantis Mantis 0.10 (including) 0.10 (including)
Mantis Mantis 0.10.0 (including) 0.10.0 (including)
Mantis Mantis 0.10.1 (including) 0.10.1 (including)
Mantis Mantis 0.10.2 (including) 0.10.2 (including)
Mantis Mantis 0.11 (including) 0.11 (including)
Mantis Mantis 0.11.0 (including) 0.11.0 (including)
Mantis Mantis 0.11.1 (including) 0.11.1 (including)
Mantis Mantis 0.12 (including) 0.12 (including)
Mantis Mantis 0.12.0 (including) 0.12.0 (including)
Mantis Mantis 0.13 (including) 0.13 (including)
Mantis Mantis 0.13.0 (including) 0.13.0 (including)
Mantis Mantis 0.13.1 (including) 0.13.1 (including)
Mantis Mantis 0.14 (including) 0.14 (including)
Mantis Mantis 0.14.0 (including) 0.14.0 (including)
Mantis Mantis 0.14.1 (including) 0.14.1 (including)
Mantis Mantis 0.14.2 (including) 0.14.2 (including)
Mantis Mantis 0.14.3 (including) 0.14.3 (including)
Mantis Mantis 0.14.4 (including) 0.14.4 (including)
Mantis Mantis 0.14.5 (including) 0.14.5 (including)
Mantis Mantis 0.14.6 (including) 0.14.6 (including)
Mantis Mantis 0.14.7 (including) 0.14.7 (including)
Mantis Mantis 0.14.8 (including) 0.14.8 (including)
Mantis Mantis 0.15 (including) 0.15 (including)
Mantis Mantis 0.15.0 (including) 0.15.0 (including)
Mantis Mantis 0.15.1 (including) 0.15.1 (including)
Mantis Mantis 0.15.2 (including) 0.15.2 (including)
Mantis Mantis 0.16 (including) 0.16 (including)
Mantis Mantis 0.16.0 (including) 0.16.0 (including)
Mantis Mantis 0.17 (including) 0.17 (including)
Mantis Mantis 0.17.0 (including) 0.17.0 (including)
Mantis Mantis 0.17.4a (including) 0.17.4a (including)
Mantis Mantis 0.18 (including) 0.18 (including)
Mantis Mantis 0.18.0 (including) 0.18.0 (including)
Mantis Mantis 0.18.0_rc1 (including) 0.18.0_rc1 (including)
Mantis Mantis 0.18.0a1 (including) 0.18.0a1 (including)
Mantis Mantis 0.18.0a2 (including) 0.18.0a2 (including)
Mantis Mantis 0.18.0a3 (including) 0.18.0a3 (including)
Mantis Mantis 0.18.0a4 (including) 0.18.0a4 (including)
Mantis Mantis 0.18.1 (including) 0.18.1 (including)
Mantis Mantis 0.18.2 (including) 0.18.2 (including)
Mantis Mantis 0.18.3 (including) 0.18.3 (including)
Mantis Mantis 0.18a1 (including) 0.18a1 (including)
Mantis Mantis 0.19.0 (including) 0.19.0 (including)
Mantis Mantis 0.19.0_rc1 (including) 0.19.0_rc1 (including)
Mantis Mantis 0.19.0a (including) 0.19.0a (including)
Mantis Mantis 0.19.0a1 (including) 0.19.0a1 (including)
Mantis Mantis 0.19.0a2 (including) 0.19.0a2 (including)
Mantis Mantis 0.19.1 (including) 0.19.1 (including)
Mantis Mantis 0.19.2 (including) 0.19.2 (including)
Mantis Mantis 0.19.3 (including) 0.19.3 (including)
Mantis Mantis 0.19.4 (including) 0.19.4 (including)
Mantis Mantis 1.0.0_rc1 (including) 1.0.0_rc1 (including)
Mantis Mantis 1.0.0_rc2 (including) 1.0.0_rc2 (including)
Mantis Mantis 1.0.0_rc3 (including) 1.0.0_rc3 (including)
Mantis Mantis 1.0.0a1 (including) 1.0.0a1 (including)
Mantis Mantis 1.0.0a2 (including) 1.0.0a2 (including)
Mantis Mantis 1.0.0a3 (including) 1.0.0a3 (including)

References