Launchpad.net

CVE 2008-4689

Mantis before 1.1.3 does not unset the session cookie during logout, which makes it easier for remote attackers to hijack sessions.

See the CVE page on Mitre.org for more details.