CVE-2002-1112 Information

Description

Mantis before 0.17.4 allows remote attackers to list project bugs without authentication by modifying the cookie that is used by the \View Bugs\ page.

Reference

http://mantisbt.sourceforge.net/advisories/2002/2002-03.txt http://marc.info/?l=bugtraq&m=102978673018271&w=2 http://www.debian.org/security/2002/dsa-153 http://www.securityfocus.com/bid/5514 https://exchange.xforce.ibmcloud.com/vulnerabilities/9899

Share on: