PublicDate: 2008-01-23 12:00:00 UTC Candidate: CVE-2008-0404 References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0404 Description: Cross-site scripting (XSS) vulnerability in Mantis before 1.1.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to the "Most active bugs" summary. Ubuntu-Description: Notes: jdstrand> per Debian-- code introduced in 1.1 series Bugs: Priority: untriaged Discovered-by: Assigned-to: CVSS: Patches_mantis: upstream_mantis: released (1.1.1) dapper_mantis: not-affected (0.19.4-2) edgy_mantis: not-affected (0.19.4-3.2) feisty_mantis: not-affected (1.0.6+dfsg-4.1) gutsy_mantis: not-affected (1.0.7+dfsg-1) devel_mantis: not-affected (1.0.8-4)