CVE-2014-9572
N/A
N/A
Summary
MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 does not properly restrict access to /*/install.php, which allows remote attackers to obtain database credentials via the install parameter with the value 4.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.securitytracker.com/id/1031633
- http://seclists.org/oss-sec/2015/q1/158
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100211
- https://www.htbridge.com/advisory/HTB23243
- https://www.mantisbt.org/bugs/view.php?id=17939
- https://www.mantisbt.org/bugs/view.php?id=17937
References
- http://www.securitytracker.com/id/1031633
- http://seclists.org/oss-sec/2015/q1/158
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100211
- https://www.htbridge.com/advisory/HTB23243
- https://www.mantisbt.org/bugs/view.php?id=17939
- https://www.mantisbt.org/bugs/view.php?id=17937
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.