Back to search
CVE-2008-4687
Published: Oct 22, 2008
Modified: Aug 7, 2024
PUBLISHED
Description
manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort parameter containing PHP sequences, which are processed by create_function within the multi_sort function in core/utility_api.php.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://bugs.gentoo.org/show_bug.cgi?id=242722
x_refsource_CONFIRM
32975
third-party-advisory
x_refsource_SECUNIA
31789
vdb-entry
x_refsource_BID
GLSA-200812-07
vendor-advisory
x_refsource_GENTOO
http://www.mantisbt.org/bugs/view.php?id=0009704
x_refsource_CONFIRM
http://www.mantisbt.org/bugs/changelog_page.php
x_refsource_CONFIRM
44611
exploit
x_refsource_EXPLOIT-DB
32314
third-party-advisory
x_refsource_SECUNIA
[oss-security] 20081019 CVE request: mantisbt < 1.1.4: RCE
mailing-list
x_refsource_MLIST
6768
exploit
x_refsource_EXPLOIT-DB
mantis-sort-code-execution(45942)
vdb-entry
x_refsource_XF
4470
third-party-advisory
x_refsource_SREASON
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now