Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2008-4688

Опубликовано: 22 окт. 2008
Источник: debian
EPSS Средний

Описание

core/string_api.php in Mantis before 1.1.3 does not check the privileges of the viewer before composing a link with issue data in the source anchor, which allows remote attackers to discover an issue's title and status via a request with a modified issue number.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mantisfixed1.1.2+dfsg-9package

EPSS

Процентиль: 96%
0.11709
Средний

Связанные уязвимости

ubuntu
почти 18 лет назад

core/string_api.php in Mantis before 1.1.3 does not check the privileges of the viewer before composing a link with issue data in the source anchor, which allows remote attackers to discover an issue's title and status via a request with a modified issue number.

nvd
почти 18 лет назад

core/string_api.php in Mantis before 1.1.3 does not check the privileges of the viewer before composing a link with issue data in the source anchor, which allows remote attackers to discover an issue's title and status via a request with a modified issue number.

github
около 4 лет назад

core/string_api.php in Mantis before 1.1.3 does not check the privileges of the viewer before composing a link with issue data in the source anchor, which allows remote attackers to discover an issue's title and status via a request with a modified issue number.

EPSS

Процентиль: 96%
0.11709
Средний