Cross-site scripting (XSS) vulnerability in config_defaults_inc.php in Mantis before 1.0 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. An original vendor bug report is referenced, but not accessible to the general public.
2006-02-13T11:06:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 4.3 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mantis | mantis | 0.17.1 | Yes |
Application | mantis | mantis | 0.17.2 | Yes |
Application | mantis | mantis | 0.17.3 | Yes |
Application | mantis | mantis | 0.17.4 | Yes |
Application | mantis | mantis | 0.17.4a | Yes |
Application | mantis | mantis | 0.17.5 | Yes |
Application | mantis | mantis | 0.18 | Yes |
Application | mantis | mantis | 0.18.0_rc1 | Yes |
Application | mantis | mantis | 0.18.0a2 | Yes |
Application | mantis | mantis | 0.18.0a3 | Yes |
Application | mantis | mantis | 0.18.0a4 | Yes |
Application | mantis | mantis | 0.18.2 | Yes |
Application | mantis | mantis | 0.18.3 | Yes |
Application | mantis | mantis | 0.18a1 | Yes |
Application | mantis | mantis | 0.19.0 | Yes |
Application | mantis | mantis | 0.19.0_rc1 | Yes |
Application | mantis | mantis | 0.19.0a | Yes |
Application | mantis | mantis | 0.19.0a1 | Yes |
Application | mantis | mantis | 0.19.0a2 | Yes |
Application | mantis | mantis | 0.19.1 | Yes |
Application | mantis | mantis | 0.19.2 | Yes |
Application | mantis | mantis | 0.19.3 | Yes |
Application | mantis | mantis | 0.19.4 | Yes |
Application | mantis | mantis | 1.0.0_rc1 | Yes |
Application | mantis | mantis | 1.0.0_rc2 | Yes |
Application | mantis | mantis | 1.0.0_rc3 | Yes |
Application | mantis | mantis | 1.0.0_rc4 | Yes |
Application | mantis | mantis | 1.0.0a1 | Yes |
Application | mantis | mantis | 1.0.0a2 | Yes |
Application | mantis | mantis | 1.0.0a3 | Yes |