3.6
CVSSv2

CVE-2003-0499

Published: 07/08/2003 Updated: 08/12/2016
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
VMScore: 320
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Mantis 0.17.5 and previous versions stores its database password in cleartext in a world-readable configuration file, which allows local users to perform unauthorized database operations.

Vulnerable Product Search on Vulmon Subscribe to Product

mantis mantis 0.17.5

Vendor Advisories

mantis, a PHP/MySQL web based bug tracking system, stores the password used to access its database in a configuration file which is world-readable This could allow a local attacker to read the password and gain read/write access to the database For the stable distribution (woody) this problem has been fixed in version 0171-3 The old stable dis ...