MantisBT是MantisBT(Mantisbt)团队的一套基于Web的开源缺陷跟踪系统。该系统以Web操作的形式提供项目管理及缺陷跟踪服务。 MantisBT 2.24.4之前版本存在安全漏洞,该漏洞源于bug_revision_view_page.php允许非特权攻击者可利用该漏洞查看私有问题的摘要字段,以及错误注释修订,通过错误注释id参数获得对潜在机密信息的访问权。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2020-28413 | 5.3 MEDIUM | MantisBT SQL注入漏洞 |
| CVE-2020-29231 | Egavilanmedia User Registration & Login System 跨站脚本漏洞 | |
| CVE-2020-35847 | Agentejo Cockpit SQL注入漏洞 | |
| CVE-2020-29230 | Egavilanmedia User Registration & Login System 跨站脚本漏洞 | |
| CVE-2020-28365 | Sentrifugo 跨站脚本漏洞 | |
| CVE-2020-29228 | Egavilanmedia User Registration & Login System SQL注入漏洞 | |
| CVE-2020-5809 | Umbraco 跨站脚本漏洞 | |
| CVE-2020-5810 | Umbraco 跨站脚本漏洞 | |
| CVE-2020-5811 | Umbraco 路径遍历漏洞 | |
| CVE-2020-29233 | WonderCMS 跨站脚本漏洞 | |
| CVE-2020-29469 | WonderCMS 跨站脚本漏洞 | |
| CVE-2020-35241 | Flatpress 跨站脚本漏洞 | |
| CVE-2020-35240 | Fluxbb 跨站脚本漏洞 | |
| CVE-2020-29477 | Invision Community 跨站脚本漏洞 | |
| CVE-2020-29594 | Rocket.Chat 授权问题漏洞 | |
| CVE-2020-35850 | Agentejo Cockpit 代码问题漏洞 | |
| CVE-2020-35846 | Agentejo Cockpit SQL注入漏洞 | |
| CVE-2020-35848 | Agentejo Cockpit SQL注入漏洞 | |
| CVE-2020-27534 | Docker Engine 路径遍历漏洞 | |
| CVE-2020-35737 | Newgen Egov Correspondence Management System 安全漏洞 |
Showing top 20 of 37 CVEs. View all on vendor page → →
No comments yet