PT-2002-2113 · Mantis · Mantis

Publicado

2002-09-10

·

Atualizado

2016-10-18

·

CVE-2002-1110

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Mantis versions 0.17.2 and earlier
Description: The issue allows remote attackers to gain privileges or perform unauthorized database operations via modified form fields, for example, to the "account update.php" endpoint, when running without magic quotes gpc enabled.
Recommendations: For Mantis versions 0.17.2 and earlier, consider disabling the account update functionality until a patch is available, and ensure magic quotes gpc is enabled to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-1110
DSA-153

Produtos afetados

Mantis