7.5
CVSSv2

CVE-2002-1114

Published: 04/10/2002 Updated: 18/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

config_inc2.php in Mantis prior to 0.17.4 allows remote malicious users to execute arbitrary code or read arbitrary files via the parameters (1) g_bottom_include_page, (2) g_top_include_page, (3) g_css_include_file, (4) g_meta_include_file, or (5) a cookie.

Vulnerable Product Search on Vulmon Subscribe to Product

mantis mantis 0.17.0

mantis mantis 0.17.3

mantis mantis 0.17.1

mantis mantis 0.17.2

Vendor Advisories

Joao Gouveia discovered an uninitialized variable which was insecurely used with file inclusions in the mantis package, a php based bug tracking system The Debian Security Team found even more similar problems When these occasions are exploited, a remote user is able to execute arbitrary code under the webserver user id on the web server hosting ...