Back to Database
Status published
Medium
CVE-2005-3091
Cross-site scripting (XSS) vulnerability in Mantis before 1.0.0rc1 allows remote...
Vulnerability Description
Cross-site scripting (XSS) vulnerability in Mantis before 1.0.0rc1 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors, as identified by bug#0005751 "thraxisp".
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2005-3091
Credits & Attribution
No credits recorded in the NVD database.
References
More from mantis
View All →CVE-2013-1811
An access control issue in MantisBT before 1.2.13 allows users...
Medium
4.3
CVE-2008-4689
Mantis before 1.1.3 does not unset the session cookie during...
High
7.5
CVE-2008-4688
core/string_api.php in Mantis before 1.1.3 does not check the privileges...
Medium
5
CVE-2008-4687
manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to...
Critical
9
CVE-2008-3333
Directory traversal vulnerability in core/lang_api.php in Mantis before 1.1.2 allows...
High
7.5
Affected Vendor
mantis
View all reports →Affected Software
mantis
Vulnerable Versions:
0.9.0, 0.9.1, 0.10.0, 0.10.1, 0.10.2, 0.11.0, 0.11.1, 0.12.0, 0.13.0, 0.13.1, 0.14.0, 0.14.1, 0.14.2, 0.14.3, 0.14.4, 0.14.5, 0.14.6, 0.14.7, 0.14.8, 0.15.0, 0.15.1, 0.15.2, 0.15.3, 0.15.4, 0.15.5, 0.15.6, 0.15.7, 0.15.8, 0.15.9, 0.15.10, 0.15.11, 0.15.12, 0.16.0, 0.16.1, 0.17.0, 0.17.1, 0.17.2, 0.17.3, 0.17.4, 0.17.4a, 0.17.5, 0.18.0, 0.18.0_rc1, 0.18.0a1, 0.18.0a2, 0.18.0a3, 0.18.0a4, 0.18.1, 0.18.2, 0.18.3, 0.19.0, 0.19.0_rc1, 0.19.0a1, 0.19.0a2, 0.19.1, 0.19.2, 1.0.0a1, 1.0.0a2, 1.0.0a3
Timeline
Official Publish:
September 28th, 2005
Last Modified:
August 7th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.