CVE-2014-9572
26.01.2015, 15:59
MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 does not properly restrict access to /*/install.php, which allows remote attackers to obtain database credentials via the install parameter with the value 4.Enginsight
Vendor | Product | Version |
---|---|---|
mantisbt | mantisbt | 𝑥 ≤ 1.2.18 |
mantisbt | mantisbt | 1.3.0:beta1 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References