Mantis 0.17.4a and earlier allows remote attackers to view private bugs by modifying the f_id bug ID parameter to (1) bug_update_advanced_page.php, (2) bug_update_page.php, (3) view_bug_advanced_page.php, or (4) view_bug_page.php.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2002-10-03 21:00
Updated : 2016-10-17 19:23
NVD link : CVE-2002-1115
Mitre link : CVE-2002-1115
JSON object : View
CWE
Products Affected
mantis
- mantis