VYPR
Unrated severityNVD Advisory· Published Oct 27, 2005· Updated Jun 16, 2026

CVE-2005-3336

CVE-2005-3336

Description

SQL injection vulnerability in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Mantisbt/Mantis2 versions
    cpe:2.3:a:mantis:mantis:0.19.2:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:mantis:mantis:0.19.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mantis:mantis:1.0.0_rc2:*:*:*:*:*:*:*
  • Range: <= 1.0.0RC2, = 0.19.2

Patches

Vulnerability mechanics

Root cause

"The advisory does not disclose the root cause beyond stating that SQL injection is possible via unknown vectors."

Attack vector

A remote attacker can send crafted input to unknown vectors in Mantis 1.0.0RC2 and 0.19.2 to inject arbitrary SQL commands. The advisory does not describe the network path, payload shape, or preconditions required. No CWE is pre-assigned in the bundle, and the reference write-up does not name a weakness class, so no CWE citation is added.

Affected code

The advisory does not specify the exact files or functions vulnerable to SQL injection in Mantis 1.0.0RC2 and 0.19.2. The referenced changelog page [ref_id=1] lists many later security fixes but does not identify the specific code path for this CVE.

What the fix does

No patch is included in the bundle. The advisory does not provide remediation guidance beyond the general note that this is a security issue. The changelog [ref_id=1] does not list a corresponding fix entry for CVE-2005-3336.

Preconditions

  • inputThe advisory does not specify any preconditions.

Generated on Jun 16, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.

References

11

News mentions

0

No linked articles in our index yet.