manage_user_page.php in Mantis 1.00rc4 and earlier does not properly handle a sort parameter containing a ' (quote) character, which allows remote attackers to trigger a SQL error that may be repeatedly reported to a user who makes subsequent web accesses with the MANTIS_MANAGE_COOKIE cookie. NOTE: this issue might be the same as vector 2 in CVE-2005-4519.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2006-02-21 18:02
Updated : 2018-10-18 09:29
NVD link : CVE-2006-0840
Mitre link : CVE-2006-0840
JSON object : View
CWE
Products Affected
mantis
- mantis