First published: Thu Oct 27 2005(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Mantis before 0.19.3 allow remote attackers to inject arbitrary web script or HTML via (1) unknown vectors involving Javascript and (2) mantis/view_all_set.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mentiss Acgv Acgvannu | =0.19.0 | |
Mentiss Acgv Acgvannu | =0.19.0_rc1 | |
Mentiss Acgv Acgvannu | =0.19.0a1 | |
Mentiss Acgv Acgvannu | =0.19.0a2 | |
Mentiss Acgv Acgvannu | =0.19.1 | |
Mentiss Acgv Acgvannu | =0.19.2 | |
Mentiss Acgv Acgvannu | =0.19.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3337 is classified as a medium severity vulnerability due to its potential to allow script injection.
To fix CVE-2005-3337, it is recommended to upgrade Mantis to version 0.19.3 or later.
CVE-2005-3337 allows remote attackers to perform cross-site scripting attacks by injecting arbitrary web scripts or HTML.
Various versions of Mantis prior to 0.19.3 are affected by CVE-2005-3337, specifically versions 0.19.0, 0.19.0_rc1, 0.19.0a1, 0.19.0a2, 0.19.1, and 0.19.2.
The common exploit method for CVE-2005-3337 involves leveraging vulnerabilities in JavaScript handling and the view_all_set.php script.