Multiple SQL injection vulnerabilities in the manage user page (manage_user_page.php) in Mantis 1.0.0rc3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) prefix and (2) sort parameters to the manage user page (manage_user_page.php), or (3) the sort parameter to view_all_set.php.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2005-12-27 17:03
Updated : 2011-03-07 18:28
NVD link : CVE-2005-4519
Mitre link : CVE-2005-4519
JSON object : View
CWE
Products Affected
mantis
- mantis