exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 18 of 18 RSS Feed

Files

mantis.txt
Posted Aug 24, 2004
Authored by Joxean Koret

Mantis is susceptible to multiple cross site scripting vulnerabilities.

tags | advisory, vulnerability, xss
SHA-256 | a6f58dd97966c39ee1d173207fb0d4d25219702ee1bad263cc675e5318ce6bef

Related Files

Mantis Bug Tracker 2.24.3 SQL Injection
Posted Jan 4, 2021
Authored by EthicalHCOP

Mantis Bug Tracker version 2.24.3 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
advisories | CVE-2020-28413
SHA-256 | 3c8957612d86d7577fdde28ee21d1df81ea67d1228ac3abae6f808678afa40ae
Mantis Bug Tracker 2.3.0 Remote Code Execution
Posted Sep 18, 2020
Authored by hyp3rlinx, Nikolas Geiselman, permanull

Mantis Bug Tracker version 2.3.0 suffers from a remote code execution vulnerability.

tags | exploit, remote, code execution
advisories | CVE-2017-7615, CVE-2019-15715
SHA-256 | c5bd41082422ed338ccc46ee3ad8d43820a3a1cd833484f28da741205e12c069
Mantis manage_proj_page PHP Code Execution
Posted May 9, 2018
Authored by EgiX, Lars Sorenson | Site metasploit.com

Mantis versions 1.1.3 and earlier are vulnerable to a post-authentication remote code execution vulnerability in the sort parameter of the manage_proj_page.php page.

tags | exploit, remote, php, code execution
advisories | CVE-2008-4687
SHA-256 | bf6d1e2f1321eacf2214a3400a3201acd1c33bb08ba4cb9b45cfa3ee93eefbeb
Mantis Bug Tracker 1.3.10 / 2.3.0 Cross Site Request Forgery
Posted May 22, 2017
Authored by hyp3rlinx | Site hyp3rlinx.altervista.org

Mantis Bug Tracker versions 1.3.10 and 2.3.0 suffer from a cross site request forgery vulnerability.

tags | exploit, csrf
advisories | CVE-2017-7620
SHA-256 | 657f51bab66ce5d5cf6800d27e2f3bc584ea834cf9cbd98479d947434a3b0ead
Mantis Bug Tracker 1.3.0 / 2.3.0 Remote Password Reset
Posted Apr 16, 2017
Authored by hyp3rlinx | Site hyp3rlinx.altervista.org

Mantis Bug Tracker versions 1.3.0 and 2.3.0 suffer from a pre-authentication remote password reset vulnerability.

tags | exploit, remote
advisories | CVE-2017-7615
SHA-256 | da0c10bca7d635dd4ba8a9cdd41f8f1b36c9490cffa05acee01ffcdf095d74d1
MantisBT 1.3.0 File Download
Posted Jun 17, 2015
Authored by indoushka

MantisBT version 1.3.0 suffers from a remote file download vulnerability.

tags | exploit, remote, info disclosure
SHA-256 | 671ba2e0e285945b42223f1727978cb7d9171580b07eb50f0c2b649e8ebddb1e
MantisBT 1.2.17 XSS / Improper Access Control / SQL Injection
Posted Jan 29, 2015
Authored by High-Tech Bridge SA | Site htbridge.com

MantisBT version 1.2.17 suffers from improper access control, cross site scripting, and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, xss, sql injection
advisories | CVE-2014-9571, CVE-2014-9572, CVE-2014-9573
SHA-256 | 66702fafa02a9dbc923285c073b3f395b675adad64da5dfa2394ca10e6440fd2
Mantis BugTracker 1.2.19 Open Redirect
Posted Jan 28, 2015
Authored by Alejo Popovici

Mantis BugTracker version 1.2.19 suffers from an open redirection vulnerability.

tags | exploit
advisories | CVE-2015-1042
SHA-256 | a4a5d3a57136e2c7c69197773c4c6f2b7d1873d9a94832d2eb5e95f58d43524e
Mantis BugTracker 1.2.17 XSS / DoS / Redirect
Posted Jan 5, 2015
Authored by Mathias Karlsson, Paul Richards, Alejo Popovici, Ryan Giobbi, Shahee Mirza

Mantis BugTracker version 1.2.17 suffers from denial of service, potential cross site scripting, and arbitrary redirection vulnerabilities.

tags | advisory, denial of service, arbitrary, vulnerability, xss
advisories | CVE-2014-6316, CVE-2014-8987, CVE-2014-9117
SHA-256 | 73dc034d9a5622082847c13fa1d43e825d41a1ee7d9873124267bbb560c947f2
MantisBT XmlImportExport Plugin PHP Code Injection
Posted Nov 18, 2014
Authored by EgiX | Site metasploit.com

This Metasploit module exploits a post-auth vulnerability found in MantisBT versions 1.2.0a3 up to 1.2.17 when the Import/Export plugin is installed. The vulnerable code exists on plugins/XmlImportExport/ImportXml.php, which receives user input through the "description" field and the "issuelink" attribute of an uploaded XML file and passes to preg_replace() function with the /e modifier. This allows a remote authenticated attacker to execute arbitrary PHP code on the remote machine.

tags | exploit, remote, arbitrary, php
advisories | CVE-2014-7146
SHA-256 | 48a52817bee791b7eaeae5d5e9a609d2d96fd14642c96da155fb1a16a00bf9c9
MantisBT 1.2.16 SQL Injection
Posted Mar 2, 2014
Authored by HauntIT

MantisBT version 1.2.16 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 920455a7475eaa40b79d5ec69566d82d5c1e669a641ca3c45e1041ff75adafed
MantisBT 1.2.7 Cross Site Scripting / Local File Inclusion
Posted Sep 7, 2011
Authored by High-Tech Bridge SA | Site htbridge.com

MantisBT version 1.2.7 suffers from cross site scripting and local file inclusion vulnerabilities.

tags | exploit, local, vulnerability, xss, file inclusion
SHA-256 | f93ea1f9463f54e352b0762b7f966c8a53d16c2feee1c1340bc0337cc98100a2
MantisBT CMS SQL Injection / Cross Site Scripting
Posted Aug 18, 2011
Authored by Net.Edit0r

MantisBT CMS suffers from cross site scripting and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, xss, sql injection
SHA-256 | d16b31ce8fbf08114e5733901215b9a05ad79cc8ab7189291699e00407f1230f
mantis-exec.txt
Posted Oct 17, 2008
Authored by EgiX

Mantis Bug Tracker versions 1.1.3 and below remote code execution exploit.

tags | exploit, remote, code execution
SHA-256 | 8f7235d1fa244d88437b93a00f10ac0a9403dda9941121e364649b305566b796
Mantis Bug Tracker 1.1.1 Multiple Vulnerabilities
Posted May 20, 2008
Authored by Francesco Ongaro, Antonio Parata | Site ush.it

Mantis Bug Tracker version 1.1.1 suffers from remote code execution, cross site scripting, and cross site request forgery vulnerabilities.

tags | exploit, remote, vulnerability, code execution, xss, csrf
SHA-256 | f69ef268367fecefac3205565ba9c1d3f5e36237f4b833741139a9350750a069
mantis-poc.tar.gz
Posted Sep 29, 2005
Authored by Joxean Koret

Mantis Bugtracker exploit scanner that looks for versions less than 1.0.0RC2 and greater than 0.18.3 which are vulnerable to XSS and variable poisoning attacks if register_globals is enabled.

tags | exploit
SHA-256 | 846b7601bdc63c621b48e9ed66d2964760dbc83607dfabd16ba2ee2080eb9cd3
mantis-poc.txt
Posted Sep 29, 2005
Authored by Joxean Koret

Mantis Bugtracker versions less than 1.0.0RC2 and greater than 0.18.3 are vulnerable to XSS and variable poisoning attacks if register_globals is enabled.

tags | exploit
SHA-256 | 85dcfcb51f4250c4f8e9ac0aa699db2ed494373073674e22eaf7e532476d42ed
mantisPHP.txt
Posted Aug 24, 2004
Authored by Joxean Koret

Mantis suffers from a remote PHP code execution vulnerability when the REGISTER_GLOBAL variable is set.

tags | advisory, remote, php, code execution
SHA-256 | a70413a0d6384063116146614076f527699b5ef8da05f1e7d3c3af253afadf40
Page 1 of 1
Back1Next

File Archive:

December 2023

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Dec 1st
    11 Files
  • 2
    Dec 2nd
    0 Files
  • 3
    Dec 3rd
    0 Files
  • 4
    Dec 4th
    0 Files
  • 5
    Dec 5th
    0 Files
  • 6
    Dec 6th
    0 Files
  • 7
    Dec 7th
    0 Files
  • 8
    Dec 8th
    0 Files
  • 9
    Dec 9th
    0 Files
  • 10
    Dec 10th
    0 Files
  • 11
    Dec 11th
    0 Files
  • 12
    Dec 12th
    0 Files
  • 13
    Dec 13th
    0 Files
  • 14
    Dec 14th
    0 Files
  • 15
    Dec 15th
    0 Files
  • 16
    Dec 16th
    0 Files
  • 17
    Dec 17th
    0 Files
  • 18
    Dec 18th
    0 Files
  • 19
    Dec 19th
    0 Files
  • 20
    Dec 20th
    0 Files
  • 21
    Dec 21st
    0 Files
  • 22
    Dec 22nd
    0 Files
  • 23
    Dec 23rd
    0 Files
  • 24
    Dec 24th
    0 Files
  • 25
    Dec 25th
    0 Files
  • 26
    Dec 26th
    0 Files
  • 27
    Dec 27th
    0 Files
  • 28
    Dec 28th
    0 Files
  • 29
    Dec 29th
    0 Files
  • 30
    Dec 30th
    0 Files
  • 31
    Dec 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close