CVE Vulnerabilities

CVE-2002-1111

Published: Oct 04, 2002 | Modified: Oct 10, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

print_all_bug_page.php in Mantis 0.17.3 and earlier does not verify the limit_reporters option, which allows remote attackers to view bug summaries for bugs that would otherwise be restricted.

Affected Software

Name Vendor Start Version End Version
Mantis Mantis 0.16.0 (including) 0.16.0 (including)
Mantis Mantis 0.16.1 (including) 0.16.1 (including)
Mantis Mantis 0.17.0 (including) 0.17.0 (including)
Mantis Mantis 0.17.1 (including) 0.17.1 (including)
Mantis Mantis 0.17.2 (including) 0.17.2 (including)
Mantis Mantis 0.17.3 (including) 0.17.3 (including)

References