Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2012-2692

Опубликовано: 17 июн. 2012
Источник: debian
EPSS Низкий

Описание

MantisBT before 1.2.11 does not check the delete_attachments_threshold permission when form_security_validation is set to OFF, which allows remote authenticated users with certain privileges to bypass intended access restrictions and delete arbitrary attachments.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mantisfixed1.2.11-1package

EPSS

Процентиль: 71%
0.0066
Низкий

Связанные уязвимости

ubuntu
больше 13 лет назад

MantisBT before 1.2.11 does not check the delete_attachments_threshold permission when form_security_validation is set to OFF, which allows remote authenticated users with certain privileges to bypass intended access restrictions and delete arbitrary attachments.

nvd
больше 13 лет назад

MantisBT before 1.2.11 does not check the delete_attachments_threshold permission when form_security_validation is set to OFF, which allows remote authenticated users with certain privileges to bypass intended access restrictions and delete arbitrary attachments.

github
больше 3 лет назад

MantisBT before 1.2.11 does not check the delete_attachments_threshold permission when form_security_validation is set to OFF, which allows remote authenticated users with certain privileges to bypass intended access restrictions and delete arbitrary attachments.

EPSS

Процентиль: 71%
0.0066
Низкий