CVE Vulnerabilities

CVE-2002-1110

Published: Oct 04, 2002 | Modified: Oct 18, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Multiple SQL injection vulnerabilities in Mantis 0.17.2 and earlier, when running without magic_quotes_gpc enabled, allows remote attackers to gain privileges or perform unauthorized database operations via modified form fields, e.g. to account_update.php.

Affected Software

Name Vendor Start Version End Version
Mantis Mantis 0.15.3 (including) 0.15.3 (including)
Mantis Mantis 0.15.4 (including) 0.15.4 (including)
Mantis Mantis 0.15.5 (including) 0.15.5 (including)
Mantis Mantis 0.15.6 (including) 0.15.6 (including)
Mantis Mantis 0.15.7 (including) 0.15.7 (including)
Mantis Mantis 0.15.8 (including) 0.15.8 (including)
Mantis Mantis 0.15.9 (including) 0.15.9 (including)
Mantis Mantis 0.15.10 (including) 0.15.10 (including)
Mantis Mantis 0.15.11 (including) 0.15.11 (including)
Mantis Mantis 0.15.12 (including) 0.15.12 (including)
Mantis Mantis 0.16.0 (including) 0.16.0 (including)
Mantis Mantis 0.16.1 (including) 0.16.1 (including)
Mantis Mantis 0.17.0 (including) 0.17.0 (including)
Mantis Mantis 0.17.1 (including) 0.17.1 (including)
Mantis Mantis 0.17.2 (including) 0.17.2 (including)

References