Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.804891
Category:Web application abuses
Title:MantisBT <= 1.2.17 Multiple Vulnerabilities
Summary:MantisBT is prone to multiple vulnerabilities.
Description:Summary:
MantisBT is prone to multiple vulnerabilities.

Vulnerability Insight:
Multiple flaws exist due to:

- an error in the 'mc_project_get_attachments' function in
api/soap/mc_project_api.php script which does not properly sanitize
user-supplied input before using it in SQL queries.

- the view_all_bug_page.php script not properly sanitizing user-supplied
input to the 'sort' and 'dir' parameters to view_all_set.php.

- null byte poisoning in LDAP authentication.

- the copy_field.php script which does not validate input to the 'dest_id'
parameter before returning it to users.

- input passed via the 'filter' parameter is not properly sanitized by the
'current_user_get_bug_filter' function in the core/current_user_api.php script.

- an error in the CAPTCHA system that is triggered upon registration.

- an error in user rights to see a given ticket and its related issues.

- application does not validate the 'return' parameter upon submission to
the /bugs/login_page.php script.

- input passed via the 'handler_id' parameter is not properly sanitized when
passed via the bug_report.php script.

- an error in the 'mci_account_get_array_by_id' function in the
api/soap/mc_account_api.php script.

Vulnerability Impact:
Successful exploitation will allow attackers
to inject or manipulate SQL queries in the backend database, execute arbitrary
script code in a user's browser session within the trust relationship between
their browser and the server, execute arbitrary PHP code, bypass security
mechanisms, conduct open redirect and phishing attacks, assign arbitrary issues,
and obtain sensitive information.

Affected Software/OS:
MantisBT version 1.2.17 and earlier.

Solution:
Update to version 1.2.18 or later.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2014-8554
BugTraq ID: 70856
http://www.securityfocus.com/bid/70856
Debian Security Information: DSA-3120 (Google Search)
http://www.debian.org/security/2015/dsa-3120
http://seclists.org/oss-sec/2014/q4/479
http://seclists.org/oss-sec/2014/q4/487
http://secunia.com/advisories/62101
XForce ISS Database: mantisbt-cve20148554-sql-injection(98457)
https://exchange.xforce.ibmcloud.com/vulnerabilities/98457
Common Vulnerability Exposure (CVE) ID: CVE-2014-9281
BugTraq ID: 71371
http://www.securityfocus.com/bid/71371
http://seclists.org/oss-sec/2014/q4/867
http://seclists.org/oss-sec/2014/q4/913
http://seclists.org/oss-sec/2014/q4/924
XForce ISS Database: mantisbt-copyfield-xss(99038)
https://exchange.xforce.ibmcloud.com/vulnerabilities/99038
Common Vulnerability Exposure (CVE) ID: CVE-2014-9280
BugTraq ID: 71361
http://www.securityfocus.com/bid/71361
http://seclists.org/oss-sec/2014/q4/864
http://seclists.org/oss-sec/2014/q4/923
XForce ISS Database: mantisbt-currentusergetbug-code-exec(99016)
https://exchange.xforce.ibmcloud.com/vulnerabilities/99016
Common Vulnerability Exposure (CVE) ID: CVE-2014-9117
BugTraq ID: 71321
http://www.securityfocus.com/bid/71321
http://www.openwall.com/lists/oss-security/2014/11/26/19
http://www.openwall.com/lists/oss-security/2014/11/27/8
XForce ISS Database: mantisbt-cve20149117-sec-bypass(99004)
https://exchange.xforce.ibmcloud.com/vulnerabilities/99004
Common Vulnerability Exposure (CVE) ID: CVE-2014-6387
http://www.openwall.com/lists/oss-security/2014/09/12/11
http://www.openwall.com/lists/oss-security/2014/09/12/14
http://www.openwall.com/lists/oss-security/2014/09/13/1
Common Vulnerability Exposure (CVE) ID: CVE-2014-9506
http://seclists.org/oss-sec/2014/q4/955
Common Vulnerability Exposure (CVE) ID: CVE-2014-9089
BugTraq ID: 71298
http://www.securityfocus.com/bid/71298
http://www.openwall.com/lists/oss-security/2014/11/25/14
http://www.openwall.com/lists/oss-security/2014/11/26/6
Common Vulnerability Exposure (CVE) ID: CVE-2014-6316
BugTraq ID: 71478
http://www.securityfocus.com/bid/71478
http://www.openwall.com/lists/oss-security/2014/12/03/11
http://seclists.org/oss-sec/2014/q4/931
XForce ISS Database: mantisbt-cve20146316-open-redirect(99128)
https://exchange.xforce.ibmcloud.com/vulnerabilities/99128
Common Vulnerability Exposure (CVE) ID: CVE-2014-9388
Common Vulnerability Exposure (CVE) ID: CVE-2014-8553
XForce ISS Database: mantisbt-cve20148553-info-disc(99257)
https://exchange.xforce.ibmcloud.com/vulnerabilities/99257
CopyrightCopyright (C) 2014 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.