CVE Database
/

CVE-2008-4687

Back to search

CVE-2008-4687

Published: Oct 22, 2008

Modified: Aug 7, 2024

PUBLISHED

Description

manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort parameter containing PHP sequences, which are processed by create_function within the multi_sort function in core/utility_api.php.

VendorProductVersions

n/a

n/a

affected
n/a

References

32975
third-party-advisory
x_refsource_SECUNIA
31789
vdb-entry
x_refsource_BID
GLSA-200812-07
vendor-advisory
x_refsource_GENTOO
44611
exploit
x_refsource_EXPLOIT-DB
32314
third-party-advisory
x_refsource_SECUNIA
6768
exploit
x_refsource_EXPLOIT-DB
mantis-sort-code-execution(45942)
vdb-entry
x_refsource_XF
4470
third-party-advisory
x_refsource_SREASON

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now