First published: Sun Apr 02 2006(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in view_all_set.php in Mantis 1.0.1, 1.0.0rc5, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) start_day, (2) start_year, and (3) start_month parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mentiss Acgv Acgvannu | =1.0 | |
Mentiss Acgv Acgvannu | =1.0.0_rc1 | |
Mentiss Acgv Acgvannu | =1.0.0_rc2 | |
Mentiss Acgv Acgvannu | =1.0.0_rc3 | |
Mentiss Acgv Acgvannu | =1.0.0_rc4 | |
Mentiss Acgv Acgvannu | =1.0.0a1 | |
Mentiss Acgv Acgvannu | =1.0.0a2 | |
Mentiss Acgv Acgvannu | =1.0.0a3 | |
Mentiss Acgv Acgvannu | =1.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1577 is classified as a moderate severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2006-1577, upgrade MantisBT to version 1.0.2 or later, which addresses these cross-site scripting vulnerabilities.
CVE-2006-1577 affects MantisBT versions 1.0.1, all release candidates up to 1.0.0rc5, and earlier versions.
The attack vectors for CVE-2006-1577 involve injecting arbitrary web script or HTML through the start_day, start_month, and start_year parameters.
Yes, CVE-2006-1577 can be exploited by remote attackers without requiring authentication.