CVE-2014-2238
05.03.2014, 16:37
SQL injection vulnerability in the manage configuration page (adm_config_report.php) in MantisBT 1.2.13 through 1.2.16 allows remote authenticated administrators to execute arbitrary SQL commands via the filter_config_id parameter.
| Vendor | Product | Version |
|---|---|---|
| mantisbt | mantisbt | 1.2.13 |
| mantisbt | mantisbt | 1.2.14 |
| mantisbt | mantisbt | 1.2.15 |
| mantisbt | mantisbt | 1.2.16 |
𝑥
= Vulnerable software versions
Ubuntu Releases
References