CVE-2008-0404

Publication date 23 January 2008

Last updated 17 July 2025


Ubuntu priority

Description

Cross-site scripting (XSS) vulnerability in Mantis before 1.1.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to the "Most active bugs" summary.

Read the notes from the security team

Status

Package Ubuntu Release Status
mantis 7.10 gutsy
Not affected
7.04 feisty
Not affected
6.10 edgy
Not affected
6.06 LTS dapper
Not affected

Notes


jdstrand

per Debian-- code introduced in 1.1 series


Access our resources on patching vulnerabilities