Sploitus

CVE-2006-0840

No indexed exploits for CVE-2006-0840 yet

manage_user_page.php in Mantis 1.00rc4 and earlier does not properly handle a sort parameter containing a ' (quote) character, which allows remote attackers to trigger a SQL error that may be repeatedly reported to a user who makes subsequent web accesses with the MANTIS_MANAGE_COOKIE cookie. NOTE: this issue might be the same as vector 2 in CVE-2005-4519.

Affected products
Mantis
Mantis
≤ 1.0.0_rc4, 0.9, 0.9.0, 0.9.1, 0.10, 0.10.0, 0.10.1, 0.10.2, 0.11, 0.11.0, 0.11.1, 0.12, 0.12.0, 0.13, 0.13.0, 0.13.1, 0.14, 0.14.0, 0.14.1, 0.14.2, 0.14.3, 0.14.4, 0.14.5, 0.14.6, 0.14.7, 0.14.8, 0.15, 0.15.0, 0.15.1, 0.15.2, 0.16, 0.16.0, 0.17, 0.17.0, 0.17.4a, 0.18, 0.18.0, 0.18.0_rc1, 0.18.0a1, 0.18.0a2
Fix
Available
CVSS 2.0
5.0 MEDIUM
EPSS
1.9% (77th percentile)
NVD status
Modified
Published
2006-02-22
CVE-2006-0840 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2006-0840 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2006-0840 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.