9
CVSSv2

CVE-2008-4687

Published: 22/10/2008 Updated: 13/05/2018
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
VMScore: 911
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

manage_proj_page.php in Mantis prior to 1.1.4 allows remote authenticated users to execute arbitrary code via a sort parameter containing PHP sequences, which are processed by create_function within the multi_sort function in core/utility_api.php.

Vulnerable Product Search on Vulmon Subscribe to Product

mantis mantis 1.0.2

mantis mantis 1.0.1

mantis mantis 1.0.4

mantis mantis 1.0.3

mantis mantis 1.1.2

mantis mantis

mantis mantis 1.0.6

mantis mantis 1.0.5

mantis mantis 1.0.8

mantis mantis 1.1.1

mantis mantis 1.0.7

mantis mantis 0.19.4

mantis mantis 0.19.3

Exploits

<?php /* -------------------------------------------------------------------------------- Mantis Bug Tracker <= 113 (manage_proj_pagephp) Remote Code Execution Exploit -------------------------------------------------------------------------------- author: EgiX mail: n0b0d13s[at]gmail[dot]com link: wwwmantis ...
## # This module requires Metasploit: metasploitcom/download # Current source: githubcom/rapid7/metasploit-framework ## class MetasploitModule < Msf::Exploit::Remote Rank = ExcellentRanking include Msf::Exploit::Remote::HttpClient def initialize(info = {}) super(update_info(info, 'Name' => 'Manti ...

Github Repositories

CVE-2008-4687-exploit Quick and dirty python exploit for CVE-2008-4687 Description by NIST: manage_proj_pagephp in Mantis before 114 allows remote authenticated users to execute arbitrary code via a sort parameter containing PHP sequences, which are processed by create_function within the multi_sort function in core/utility_apiphp

Python script to obtain RCE on Mantis Bug Tracker prior to version 1.2.x Check CVE-2008-4687 for additional information

mantis_rce Python script to obtain RCE on Mantis Bug Tracker prior to version 12x Check CVE-2008-4687 for additional information