Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-6387

Опубликовано: 22 окт. 2014
Источник: debian
EPSS Низкий

Описание

gpc_api.php in MantisBT 1.2.17 and earlier allows remote attackers to bypass authenticated via a password starting will a null byte, which triggers an unauthenticated bind.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mantisremovedpackage
mantisend-of-lifesqueezepackage

Примечания

  • http://www.mantisbt.org/bugs/view.php?id=17640

  • http://github.com/mantisbt/mantisbt/commit/215968fa8 (1.2.x branch)

  • http://github.com/mantisbt/mantisbt/commit/fc02c46ee (master branch)

EPSS

Процентиль: 80%
0.02103
Низкий

Связанные уязвимости

ubuntu
почти 12 лет назад

gpc_api.php in MantisBT 1.2.17 and earlier allows remote attackers to bypass authenticated via a password starting will a null byte, which triggers an unauthenticated bind.

nvd
почти 12 лет назад

gpc_api.php in MantisBT 1.2.17 and earlier allows remote attackers to bypass authenticated via a password starting will a null byte, which triggers an unauthenticated bind.

github
около 4 лет назад

gpc_api.php in MantisBT 1.2.17 and earlier allows remote attackers to bypass authenticated via a password starting will a null byte, which triggers an unauthenticated bind.

EPSS

Процентиль: 80%
0.02103
Низкий