CVE Vulnerabilities

CVE-2002-1114

Published: Oct 04, 2002 | Modified: Oct 18, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

config_inc2.php in Mantis before 0.17.4 allows remote attackers to execute arbitrary code or read arbitrary files via the parameters (1) g_bottom_include_page, (2) g_top_include_page, (3) g_css_include_file, (4) g_meta_include_file, or (5) a cookie.

Affected Software

Name Vendor Start Version End Version
Mantis Mantis 0.17.0 (including) 0.17.0 (including)
Mantis Mantis 0.17.1 (including) 0.17.1 (including)
Mantis Mantis 0.17.2 (including) 0.17.2 (including)
Mantis Mantis 0.17.3 (including) 0.17.3 (including)

References