PT-2002-2113 · Mantis · Mantis
Publicado
2002-09-10
·
Atualizado
2016-10-18
·
CVE-2002-1110
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Mantis versions 0.17.2 and earlier
Description:
The issue allows remote attackers to gain privileges or perform unauthorized database operations via modified form fields, for example, to the "account update.php" endpoint, when running without magic quotes gpc enabled.
Recommendations:
For Mantis versions 0.17.2 and earlier, consider disabling the account update functionality until a patch is available, and ensure magic quotes gpc is enabled to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Mantis