5
CVSSv2

CVE-2006-6574

Published: 15/12/2006 Updated: 29/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Mantis prior to 1.1.0a2 does not implement per-item access control for Issue History (Bug History), which allows remote malicious users to obtain sensitive information by reading the Change column, as demonstrated by the Change column of a custom field.

Vulnerable Product Search on Vulmon Subscribe to Product

mantis mantis 1.0.6

mantis mantis 1.0.2

mantis mantis 1.0.4

mantis mantis 1.0.0 rc3

mantis mantis 1.0.0 rc1

mantis mantis 1.0.0 rc2

mantis mantis 1.0.0

mantis mantis 1.0.1

mantis mantis 1.0.0 rc4

mantis mantis 1.0.3

mantis mantis 1.0.5

mantis mantis 1.0.0a3

mantis mantis 1.0.0a1

mantis mantis 1.0.0a2

mantis mantis 1.0.0 rc5

mantis mantis

Vendor Advisories

Several remote vulnerabilities have been discovered in Mantis, a web based bug tracking system The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2006-6574 Custom fields were not appropriately protected by per-item access control, allowing for sensitive data to be published CVE-2007-6611 Multiple ...