7.5
CVSSv2

CVE-2005-4518

Published: 28/12/2005 Updated: 08/03/2011
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Mantis prior to 0.19.4 allows remote malicious users to bypass the file upload size restriction by modifying the max_file_size parameter to (1) bug_file_add.php, (2) bug_report.php, (3) bug_report_advanced_page.php, and (4) proj_doc_add_page.php.

Vulnerable Product Search on Vulmon Subscribe to Product

Vendor Advisories

Several security related problems have been discovered in Mantis, a web-based bug tracking system The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2005-4238 Missing input sanitising allows remote attackers to inject arbitrary web script or HTML CVE-2005-4518 Tobias Klein discovered that Mantis a ...