Damien Regad
65 exploits
Active since Jun 2012
MantisBT < 1.3.20 - Authenticated Remote Code Execution via Command Injection
CVSS 7.2
MantisBT < 1.3.20 - Authenticated Remote Code Execution via Command Injection
CVSS 7.2
MantisBT < 1.3.20 - Authenticated Remote Code Execution via Command Injection
CVSS 7.2
MantisBT < 1.3.20 - Authenticated Remote Code Execution via Command Injection
CVSS 7.2
MantisBT < 2.24.3 - Missing Authorization for Private Attachment Download
CVSS 4.3
MantisBT < 2.27.2 - Denial of Service via Oversized Issue Note Submission
CVSS 6.5
MantisBT < 2.27.2 - Denial of Service via Oversized Issue Note Submission
CVSS 6.5
MantisBT Vulnerable to Stored HTML Injection in Tag Delete Confirmation
CVSS 6.1
MantisBT Vulnerable to Stored HTML Injection in Tag Delete Confirmation
CVSS 6.1
MantisBT has Stored HTML Injection / XSS when displaying Tags in Timeline
CVSS 6.1
MantisBT < 2.28.1 - Authentication Bypass via SOAP API Password Parameter
CVSS 9.8
MantisBT 1.2.12-1.2.14 - Denial of Service via Filter Criteria Resource Consumption
MantisBT < 1.2.19 - Authenticated Unauthorized File Download via Project Documentation Feature
CVSS 5.3
ADOdb Library for PHP < 5.20.7 - SQL Injection via PDO Driver qstr Method
CVSS 9.8
MantisBT < 1.3.12 and 2.x < 2.5.2 - Cross-Site Scripting via Installation Script Variables
CVSS 6.1
MantisBT 2.0.0-2.5.1 - Cross-Site Scripting in Manage User Page Filter Field
CVSS 6.1
MantisBT < 1.3.7 and 2.x < 2.2.1 - Cross-Site Scripting via 'action_type' Parameter
CVSS 6.1
MantisBT < 2.2.0 - Cross-Site Scripting via view_type Parameter
CVSS 6.1
MantisBT 2.3.0-2.3.1 - Cross-Site Scripting via PATH_INFO in Timeline Include Page
CVSS 6.1
MantisBT 2.1.0-2.15.0 - Cross-Site Scripting via View Filters Page PATH_INFO
CVSS 6.1
MantisBT < 2.10.0 - Path Disclosure via Invalid Filter Parameter
CVSS 5.3
MantisBT < 1.3.14 and 2.0.0 - Authenticated Private Issue Data Exposure via Cloning
CVSS 6.5
MantisBT < 2.21.1 - Stored Cross-Site Scripting via Timeline Attachment Filename
CVSS 9.6
MantisBT < 2.24.3 - Cross-Site Scripting via Custom Field Regular Expression
CVSS 4.8
MantisBT < 2.24.3 - Missing Authorization for Private Attachment Download
CVSS 4.3