Back to Database
Status published
Low
CVE-2008-3331
Cross-site scripting (XSS) vulnerability in return_dynamic_filters.php in Mantis before 1.1.2...
Vulnerability Description
Cross-site scripting (XSS) vulnerability in return_dynamic_filters.php in Mantis before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the filter_target parameter.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2008-3331
Credits & Attribution
No credits recorded in the NVD database.
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42549
- http://www.mantisbt.org/bugs/changelog_page.php
- http://secunia.com/advisories/30270
- http://marc.info/?l=bugtraq&m=121130774617956&w=4
- http://www.gentoo.org/security/en/glsa/glsa-200809-10.xml
- https://www.exploit-db.com/exploits/5657
- http://secunia.com/advisories/31972
- http://www.vupen.com/english/advisories/2008/1598/references
- http://www.securityfocus.com/bid/29297
- http://securityreason.com/securityalert/4044
More from mantis
View All →CVE-2013-1811
An access control issue in MantisBT before 1.2.13 allows users...
Medium
4.3
CVE-2008-4689
Mantis before 1.1.3 does not unset the session cookie during...
High
7.5
CVE-2008-4688
core/string_api.php in Mantis before 1.1.3 does not check the privileges...
Medium
5
CVE-2008-4687
manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to...
Critical
9
CVE-2008-3333
Directory traversal vulnerability in core/lang_api.php in Mantis before 1.1.2 allows...
High
7.5
Affected Vendor
mantis
View all reports →Affected Software
mantis
Vulnerable Versions:
0, 0.9, 0.9.0, 0.9.1, 0.10, 0.10.0, 0.10.1, 0.10.2, 0.11, 0.11.0, 0.11.1, 0.12, 0.12.0, 0.13, 0.13.0, 0.13.1, 0.14, 0.14.0, 0.14.1, 0.14.2, 0.14.3, 0.14.4, 0.14.5, 0.14.6, 0.14.7, 0.14.8, 0.15, 0.15.0, 0.15.1, 0.15.2, 0.15.3, 0.15.4, 0.15.5, 0.15.6, 0.15.7, 0.15.8, 0.15.9, 0.15.10, 0.15.11, 0.15.12, 0.16, 0.16.0, 0.16.1, 0.17, 0.17.0, 0.17.1, 0.17.2, 0.17.3, 0.17.4, 0.17.4a, 0.17.5, 0.18, 0.18.0, 0.18.0_rc1, 0.18.0a1, 0.18.0a2, 0.18.0a3, 0.18.0a4, 0.18.1, 0.18.2, 0.18.3, 0.18a1, 0.19, 0.19.0, 0.19.0_rc1, 0.19.0a, 0.19.0a1, 0.19.0a2, 0.19.1, 0.19.2, 0.19.3, 0.19.4, 1.0, 1.0.0, 1.0.0_rc1, 1.0.0_rc2, 1.0.0_rc3, 1.0.0_rc4, 1.0.0_rc5, 1.0.0a1, 1.0.0a2, 1.0.0a3, 1.0.0rc1, 1.0.0rc2, 1.0.0rc3, 1.0.0rc4, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.1, 1.1.0, 1.1.0a1
Timeline
Official Publish:
July 27th, 2008
Last Modified:
August 7th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.