Mantis 1.0.0rc3 and earlier discloses private bugs via public RSS feeds, which allows remote attackers to obtain sensitive information.
References
Link | Resource |
---|---|
http://www.trapkit.de/advisories/TKADV2005-11-002.txt | Exploit Vendor Advisory |
http://sourceforge.net/project/shownotes.php?release_id=377934&group_id=14963 | |
http://secunia.com/advisories/18181/ | Patch Vendor Advisory |
http://secunia.com/advisories/18221 | Vendor Advisory |
http://www.debian.org/security/2005/dsa-944 | |
http://secunia.com/advisories/18481 | |
http://www.vupen.com/english/advisories/2005/3064 |
Configurations
Configuration 1 (hide)
|
Information
Published : 2005-12-27 17:03
Updated : 2011-03-07 18:28
NVD link : CVE-2005-4523
Mitre link : CVE-2005-4523
JSON object : View
CWE
Products Affected
mantis
- mantis