Description
MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 does not properly restrict access to /*/install.php, which allows remote attackers to obtain database credentials via the install parameter with the value 4.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2014-9386 | MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 does not properly restrict access to /*/install.php, which allows remote attackers to obtain database credentials via the install parameter with the value 4. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T13:47:41.829Z
Reserved: 2015-01-07T00:00:00.000Z
Link: CVE-2014-9572
No data.
Status : Deferred
Published: 2015-01-26T15:59:11.643
Modified: 2025-04-12T10:46:40.837
Link: CVE-2014-9572
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD