MantisBT 'admin/upgrade_unattended.php' Security Bypass Vulnerability
BID:71359
Info
MantisBT 'admin/upgrade_unattended.php' Security Bypass Vulnerability
| Bugtraq ID: | 71359 |
| Class: | Design Error |
| CVE: |
CVE-2014-9279 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 29 2014 12:00AM |
| Updated: | Dec 09 2014 12:55AM |
| Credit: | Matthias Karlsson |
| Vulnerable: |
Mantisbt Mantisbt 1.2.9 Mantisbt Mantisbt 1.2.8 Mantisbt Mantisbt 1.2.7 Mantisbt Mantisbt 1.2.6 Mantisbt Mantisbt 1.2.4 Mantisbt Mantisbt 1.2.3 Mantisbt Mantisbt 1.1.8 Mantisbt Mantisbt 1.1.7 Mantisbt Mantisbt 1.1.5 Mantisbt Mantisbt 1.2.2 Mantisbt Mantisbt 1.2.1 Mantisbt Mantisbt 1.1.6 Mantisbt Mantisbt 1.1.4 Mantisbt Mantisbt 1.1.2 Mantisbt Mantisbt 1.1.1 |
| Not Vulnerable: | |
Discussion
MantisBT 'admin/upgrade_unattended.php' Security Bypass Vulnerability
MantisBT is prone to a security-bypass vulnerability.
An attacker can leverage this issue to bypass security restrictions and gain access to potentially sensitive information. This may aid in further attacks.
The following versions are vulnerable:
Mantisbt 1.2.17 and prior
Mantisbt 1.1.0a3 and later
MantisBT is prone to a security-bypass vulnerability.
An attacker can leverage this issue to bypass security restrictions and gain access to potentially sensitive information. This may aid in further attacks.
The following versions are vulnerable:
Mantisbt 1.2.17 and prior
Mantisbt 1.1.0a3 and later
Exploit / POC
MantisBT 'admin/upgrade_unattended.php' Security Bypass Vulnerability
Attackers can exploit this issue using browser or readily available tools.
Attackers can exploit this issue using browser or readily available tools.
Solution / Fix
MantisBT 'admin/upgrade_unattended.php' Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
MantisBT 'admin/upgrade_unattended.php' Security Bypass Vulnerability
References:
References: