Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2006-0840
Description:manage_user_page.php in Mantis 1.00rc4 and earlier does not properly handle a sort parameter containing a ' (quote) character, which allows remote attackers to trigger a SQL error that may be repeatedly reported to a user who makes subsequent web accesses with the MANTIS_MANAGE_COOKIE cookie. NOTE: this issue might be the same as vector 2 in CVE-2005-4519.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2006-0840
BugTraq ID: 16657
http://www.securityfocus.com/bid/16657
Bugtraq: 20060215 [BuHa-Security] Multiple Vulnerabilities in Mantis 1.00rc4 (Google Search)
http://www.securityfocus.com/archive/1/425046/100/0/threaded
http://morph3us.org/advisories/20060214-mantis-100rc4.txt
http://sourceforge.net/project/showfiles.php?group_id=14963&package_id=12175&release_id=386059
http://sourceforge.net/project/shownotes.php?release_id=386059&group_id=14963
XForce ISS Database: mantis-manageuserpagesql-injection(24726)
https://exchange.xforce.ibmcloud.com/vulnerabilities/24726




© 1998-2025 E-Soft Inc. All rights reserved.