5
CVSSv2

CVE-2002-1112

Published: 04/10/2002 Updated: 10/10/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Mantis prior to 0.17.4 allows remote malicious users to list project bugs without authentication by modifying the cookie that is used by the "View Bugs" page.

Vulnerable Product Search on Vulmon Subscribe to Product

mantis mantis 0.15.10

mantis mantis 0.15.8

mantis mantis 0.15.9

mantis mantis 0.15.6

mantis mantis 0.15.7

mantis mantis 0.17.2

mantis mantis 0.17.3

mantis mantis 0.15.3

mantis mantis 0.15.4

mantis mantis 0.15.5

mantis mantis 0.17.0

mantis mantis 0.17.1

mantis mantis 0.15.11

mantis mantis 0.15.12

mantis mantis 0.16.0

mantis mantis 0.16.1

Vendor Advisories

Joao Gouveia discovered an uninitialized variable which was insecurely used with file inclusions in the mantis package, a php based bug tracking system The Debian Security Team found even more similar problems When these occasions are exploited, a remote user is able to execute arbitrary code under the webserver user id on the web server hosting ...