10
CVSSv2

CVE-2002-1110

Published: 04/10/2002 Updated: 18/10/2016
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple SQL injection vulnerabilities in Mantis 0.17.2 and previous versions, when running without magic_quotes_gpc enabled, allows remote malicious users to gain privileges or perform unauthorized database operations via modified form fields, e.g. to account_update.php.

Vulnerable Product Search on Vulmon Subscribe to Product

mantis mantis 0.15.10

mantis mantis 0.15.7

mantis mantis 0.15.8

mantis mantis 0.15.5

mantis mantis 0.15.6

mantis mantis 0.17.1

mantis mantis 0.17.2

mantis mantis 0.15.3

mantis mantis 0.15.4

mantis mantis 0.16.1

mantis mantis 0.17.0

mantis mantis 0.15.11

mantis mantis 0.15.12

mantis mantis 0.15.9

mantis mantis 0.16.0

Vendor Advisories

Joao Gouveia discovered an uninitialized variable which was insecurely used with file inclusions in the mantis package, a php based bug tracking system The Debian Security Team found even more similar problems When these occasions are exploited, a remote user is able to execute arbitrary code under the webserver user id on the web server hosting ...