MantisBT 'core/file_api.php' Security Bypass Vulnerability
BID:71104
Info
MantisBT 'core/file_api.php' Security Bypass Vulnerability
| Bugtraq ID: | 71104 |
| Class: | Access Validation Error |
| CVE: |
CVE-2014-8988 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 15 2014 12:00AM |
| Updated: | Jan 12 2015 12:01AM |
| Credit: | Florian Fuchs |
| Vulnerable: |
Mantisbt Mantisbt 1.2.9 Mantisbt Mantisbt 1.2.8 Mantisbt Mantisbt 1.2.7 Mantisbt Mantisbt 1.2.6 Mantisbt Mantisbt 1.2.4 Mantisbt Mantisbt 1.2.3 Mantisbt Mantisbt 1.1.8 Mantisbt Mantisbt 1.1.7 Mantisbt Mantisbt 1.1.5 Mantisbt Mantisbt 1.0.8 Mantisbt Mantisbt 1.0.7 Mantisbt Mantisbt 1.0.6 Mantisbt Mantisbt 1.0.2 Mantisbt Mantisbt 0.19.4 Mantisbt Mantisbt 0.19.3 Mantisbt Mantisbt 1.2.2 Mantisbt Mantisbt 1.2.1 Mantisbt Mantisbt 1.1.6 Mantisbt Mantisbt 1.1.4 Mantisbt Mantisbt 1.1.2 Mantisbt Mantisbt 1.1.1 Mantisbt Mantisbt 1.1.0 Mantisbt Mantisbt 1.0.5 Mantisbt Mantisbt 1.0.4 Mantisbt Mantisbt 1.0.3 Mantisbt Mantisbt 1.0.2 Mantisbt Mantisbt 1.0.1 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: | |
Discussion
MantisBT 'core/file_api.php' Security Bypass Vulnerability
MantisBT is prone to a security-bypass vulnerability.
An attacker can leverage this issue to bypass security restrictions and gain access to potentially sensitive information. This may aid in further attacks.
Mantisbt 1.2.17 and prior are vulnerable.
MantisBT is prone to a security-bypass vulnerability.
An attacker can leverage this issue to bypass security restrictions and gain access to potentially sensitive information. This may aid in further attacks.
Mantisbt 1.2.17 and prior are vulnerable.
Exploit / POC
MantisBT 'core/file_api.php' Security Bypass Vulnerability
An attacker can exploit this issue using a browser.
An attacker can exploit this issue using a browser.
Solution / Fix
MantisBT 'core/file_api.php' Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
MantisBT 'core/file_api.php' Security Bypass Vulnerability
References:
References: