5
CVSSv2

CVE-2002-1111

Published: 04/10/2002 Updated: 10/10/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

print_all_bug_page.php in Mantis 0.17.3 and previous versions does not verify the limit_reporters option, which allows remote malicious users to view bug summaries for bugs that would otherwise be restricted.

Vulnerable Product Search on Vulmon Subscribe to Product

mantis mantis 0.16.0

mantis mantis 0.16.1

mantis mantis 0.17.0

mantis mantis 0.17.1

mantis mantis 0.17.2

mantis mantis 0.17.3

Vendor Advisories

Joao Gouveia discovered an uninitialized variable which was insecurely used with file inclusions in the mantis package, a php based bug tracking system The Debian Security Team found even more similar problems When these occasions are exploited, a remote user is able to execute arbitrary code under the webserver user id on the web server hosting ...