Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-6316

Опубликовано: 12 дек. 2014
Источник: debian
EPSS Низкий

Описание

core/string_api.php in MantisBT before 1.2.18 does not properly categorize URLs when running under the web root, which allows remote attackers to conduct open redirect and phishing attacks via a crafted URL in the return parameter to login_page.php.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mantisremovedpackage
mantisend-of-lifesqueezepackage

Примечания

  • http://github.com/mantisbt/mantisbt/commit/e66ecc9f

  • https://www.mantisbt.org/bugs/view.php?id=17648

  • https://www.mantisbt.org/bugs/view.php?id=17362

  • https://www.mantisbt.org/bugs/view.php?id=17698

  • https://www.mantisbt.org/bugs/view.php?id=17811

EPSS

Процентиль: 69%
0.00605
Низкий

Связанные уязвимости

ubuntu
около 11 лет назад

core/string_api.php in MantisBT before 1.2.18 does not properly categorize URLs when running under the web root, which allows remote attackers to conduct open redirect and phishing attacks via a crafted URL in the return parameter to login_page.php.

nvd
около 11 лет назад

core/string_api.php in MantisBT before 1.2.18 does not properly categorize URLs when running under the web root, which allows remote attackers to conduct open redirect and phishing attacks via a crafted URL in the return parameter to login_page.php.

github
больше 3 лет назад

core/string_api.php in MantisBT before 1.2.18 does not properly categorize URLs when running under the web root, which allows remote attackers to conduct open redirect and phishing attacks via a crafted URL in the return parameter to login_page.php.

EPSS

Процентиль: 69%
0.00605
Низкий