PT-2002-2113 · Mantis · Mantis
Published
2002-09-10
·
Updated
2016-10-18
·
CVE-2002-1110
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Mantis versions 0.17.2 and earlier
Description:
The issue allows remote attackers to gain privileges or perform unauthorized database operations via modified form fields, for example, to the "account update.php" endpoint, when running without magic quotes gpc enabled.
Recommendations:
For Mantis versions 0.17.2 and earlier, consider disabling the account update functionality until a patch is available, and ensure magic quotes gpc is enabled to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mantis