Multiple cross-site scripting (XSS) vulnerabilities in Mantis before 0.19.3 allow remote attackers to inject arbitrary web script or HTML via (1) unknown vectors involving Javascript and (2) mantis/view_all_set.php.
http://bugs.mantisbt.org/changelog_page.php
http://secunia.com/advisories/17362
http://sourceforge.net/project/shownotes.php?release_id=362673
Source: MITRE
Published: 2005-10-27
Updated: 2008-09-05
Type: NVD-CWE-Other
Base Score: 4.3
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N
Impact Score: 2.9
Exploitability Score: 8.6
Severity: MEDIUM