Damien Regad
65 exploits
Active since Jun 2012
MantisBT < 2.24.3 - Cross-Site Scripting via Custom Field Name
CVSS 4.8
MantisBT Source Integration < 1.6.2 and 2.x < 2.3.1 - Stored Cross-Site Scripting via Repository Name
CVSS 6.1
adodb < 5.20.21 - Authentication Bypass
CVSS 9.1
MantisBT < 2.25.3 - CSV Injection via CSV Export API
CVSS 7.8
MantisBT < 2.25.8 - Unauthorized Private Project Name Exposure via Wiki Page ID Enumeration
CVSS 4.3
MantisBT < 2.26.1 - Unauthenticated Account Hijacking via Password Reset Link Poisoning
CVSS 8.3
MantisBT < 2.26.2 - Unauthenticated Account Takeover via Password Reset Token Reuse
CVSS 7.3
MantisBT < 2.26.2 - Stored Cross-Site Scripting via Custom Field Name
CVSS 6.6
MantisBT < 2.26.4 - Authenticated Exposure of Sensitive Information via Crafted POST Request
CVSS 6.5
ADOdb < 5.22.9 - SQL Injection via pg_insert_id()
CVSS 10.0
MantisBT < 2.27.2 - Denial of Service via Oversized Issue Note Submission
CVSS 6.5
MantisBT < 2.27.2 - Authentication Bypass via MD5 Hash Type Juggling
CVSS 9.1
ADOdb < 5.22.10 - SQL Injection via metaColumns(), metaForeignKeys() or metaIndexes() Table Parameter
CVSS 10.0
MantisBT < 2.27.2 - Information Disclosure via Unvalidated Email Address Change
CVSS 5.4
MantisBT < 2.27.2 - Improper Authorization via Copy From Action
CVSS 4.3