Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2012-5522

Опубликовано: 16 нояб. 2012
Источник: debian

Описание

MantisBT before 1.2.12 does not use an expected default value during decisions about whether a user may modify the status of a bug, which allows remote authenticated users to bypass intended access restrictions and make status changes by leveraging a blank value for a per-status setting.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mantisfixed1.2.11-1.2package
mantisend-of-lifesqueezepackage

Примечания

  • http://www.mantisbt.org/bugs/view.php?id=14496

Связанные уязвимости

ubuntu
почти 14 лет назад

MantisBT before 1.2.12 does not use an expected default value during decisions about whether a user may modify the status of a bug, which allows remote authenticated users to bypass intended access restrictions and make status changes by leveraging a blank value for a per-status setting.

nvd
почти 14 лет назад

MantisBT before 1.2.12 does not use an expected default value during decisions about whether a user may modify the status of a bug, which allows remote authenticated users to bypass intended access restrictions and make status changes by leveraging a blank value for a per-status setting.

github
больше 4 лет назад

MantisBT before 1.2.12 does not use an expected default value during decisions about whether a user may modify the status of a bug, which allows remote authenticated users to bypass intended access restrictions and make status changes by leveraging a blank value for a per-status setting.