vendor:
Mantis Bug Tracker
by:
Antonio "s4tan" Parata and Francesco "ascii" Ongaro from USH Team
7.5
CVSS
HIGH
Multiple Vulnerabilities
79,352,78
CWE
Product Name: Mantis Bug Tracker
Affected Version From: Mantis 1.1.1
Affected Version To: Mantis 1.1.1
Patch Exists: YES
Related CWE: CVE-2008-XXXX
CPE: 2.3:a:mantisbt:mantis:1.1.1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2008
Mantis Bug Tracker 1.1.1 Multiple Vulnerabilities
Multiple vulnerabilities exist in Mantis software (XSS, CSRF, Remote Code Execution). We have found an XSS vulnerability in return_dynamic_filters.php. In order to exploit this vulnerability the attacker must be authenticated. There is a Cross Site Request Forgery vulnerability in the software. If a logged in user with administrator privileges clicks on the following url, a new user 'foo' with administrator privileges is created. We have found a Remote Code Execution vulnerability in adm_config_set.php. In order to exploit this vulnerability the attacker must be authenticated as administrator.
Mitigation:
The vendor has released a patch to fix the vulnerabilities.