Lucene search

K
cveRedhatCVE-2013-4460
HistoryJan 10, 2014 - 3:55 p.m.

CVE-2013-4460

2014-01-1015:55:03
CWE-79
redhat
web.nvd.nist.gov
41
cve-2013-4460
xss
vulnerability
mantisbt
web security
nvd

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

46.2%

Cross-site scripting (XSS) vulnerability in account_sponsor_page.php in MantisBT 1.0.0 through 1.2.15 allows remote authenticated users to inject arbitrary web script or HTML via a project name.

Affected configurations

Nvd
Node
mantisbtmantisbtMatch1.0.0
OR
mantisbtmantisbtMatch1.0.0a1
OR
mantisbtmantisbtMatch1.0.0a2
OR
mantisbtmantisbtMatch1.0.0a3
OR
mantisbtmantisbtMatch1.0.0rc1
OR
mantisbtmantisbtMatch1.0.0rc2
OR
mantisbtmantisbtMatch1.0.0rc3
OR
mantisbtmantisbtMatch1.0.0rc4
OR
mantisbtmantisbtMatch1.0.0rc5
OR
mantisbtmantisbtMatch1.0.1
OR
mantisbtmantisbtMatch1.0.2
OR
mantisbtmantisbtMatch1.0.3
OR
mantisbtmantisbtMatch1.0.4
OR
mantisbtmantisbtMatch1.0.5
OR
mantisbtmantisbtMatch1.0.6
OR
mantisbtmantisbtMatch1.0.7
OR
mantisbtmantisbtMatch1.0.8
OR
mantisbtmantisbtMatch1.0.9
OR
mantisbtmantisbtMatch1.1.0
OR
mantisbtmantisbtMatch1.1.0a1
OR
mantisbtmantisbtMatch1.1.0a2
OR
mantisbtmantisbtMatch1.1.0a3
OR
mantisbtmantisbtMatch1.1.0a4
OR
mantisbtmantisbtMatch1.1.0rc1
OR
mantisbtmantisbtMatch1.1.0rc2
OR
mantisbtmantisbtMatch1.1.0rc3
OR
mantisbtmantisbtMatch1.1.1
OR
mantisbtmantisbtMatch1.1.2
OR
mantisbtmantisbtMatch1.1.3
OR
mantisbtmantisbtMatch1.1.4
OR
mantisbtmantisbtMatch1.1.5
OR
mantisbtmantisbtMatch1.1.6
OR
mantisbtmantisbtMatch1.1.7
OR
mantisbtmantisbtMatch1.1.8
OR
mantisbtmantisbtMatch1.1.9
OR
mantisbtmantisbtMatch1.2.0
OR
mantisbtmantisbtMatch1.2.0alpha1
OR
mantisbtmantisbtMatch1.2.0alpha2
OR
mantisbtmantisbtMatch1.2.0alpha3
OR
mantisbtmantisbtMatch1.2.0rc1
OR
mantisbtmantisbtMatch1.2.0rc2
OR
mantisbtmantisbtMatch1.2.1
OR
mantisbtmantisbtMatch1.2.2
OR
mantisbtmantisbtMatch1.2.3
OR
mantisbtmantisbtMatch1.2.4
OR
mantisbtmantisbtMatch1.2.5
OR
mantisbtmantisbtMatch1.2.6
OR
mantisbtmantisbtMatch1.2.7
OR
mantisbtmantisbtMatch1.2.8
OR
mantisbtmantisbtMatch1.2.9
OR
mantisbtmantisbtMatch1.2.10
OR
mantisbtmantisbtMatch1.2.11
OR
mantisbtmantisbtMatch1.2.13
OR
mantisbtmantisbtMatch1.2.14
OR
mantisbtmantisbtMatch1.2.15
VendorProductVersionCPE
mantisbtmantisbt1.0.0cpe:2.3:a:mantisbt:mantisbt:1.0.0:*:*:*:*:*:*:*
mantisbtmantisbt1.0.0cpe:2.3:a:mantisbt:mantisbt:1.0.0:a1:*:*:*:*:*:*
mantisbtmantisbt1.0.0cpe:2.3:a:mantisbt:mantisbt:1.0.0:a2:*:*:*:*:*:*
mantisbtmantisbt1.0.0cpe:2.3:a:mantisbt:mantisbt:1.0.0:a3:*:*:*:*:*:*
mantisbtmantisbt1.0.0cpe:2.3:a:mantisbt:mantisbt:1.0.0:rc1:*:*:*:*:*:*
mantisbtmantisbt1.0.0cpe:2.3:a:mantisbt:mantisbt:1.0.0:rc2:*:*:*:*:*:*
mantisbtmantisbt1.0.0cpe:2.3:a:mantisbt:mantisbt:1.0.0:rc3:*:*:*:*:*:*
mantisbtmantisbt1.0.0cpe:2.3:a:mantisbt:mantisbt:1.0.0:rc4:*:*:*:*:*:*
mantisbtmantisbt1.0.0cpe:2.3:a:mantisbt:mantisbt:1.0.0:rc5:*:*:*:*:*:*
mantisbtmantisbt1.0.1cpe:2.3:a:mantisbt:mantisbt:1.0.1:*:*:*:*:*:*:*
Rows per page:
1-10 of 551

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

46.2%