Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2qwf-fhm6-c4w3

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью

Описание

SQL injection vulnerability in the mci_file_get function in api/soap/mc_file_api.php in MantisBT before 1.2.16 allows remote attackers to execute arbitrary SQL commands via a crafted envelope tag in a mc_issue_attachment_get SOAP request.

SQL injection vulnerability in the mci_file_get function in api/soap/mc_file_api.php in MantisBT before 1.2.16 allows remote attackers to execute arbitrary SQL commands via a crafted envelope tag in a mc_issue_attachment_get SOAP request.

EPSS

Процентиль: 69%
0.00605
Низкий

Дефекты

CWE-89

Связанные уязвимости

ubuntu
почти 12 лет назад

SQL injection vulnerability in the mci_file_get function in api/soap/mc_file_api.php in MantisBT before 1.2.16 allows remote attackers to execute arbitrary SQL commands via a crafted envelope tag in a mc_issue_attachment_get SOAP request.

nvd
почти 12 лет назад

SQL injection vulnerability in the mci_file_get function in api/soap/mc_file_api.php in MantisBT before 1.2.16 allows remote attackers to execute arbitrary SQL commands via a crafted envelope tag in a mc_issue_attachment_get SOAP request.

debian
почти 12 лет назад

SQL injection vulnerability in the mci_file_get function in api/soap/m ...

EPSS

Процентиль: 69%
0.00605
Низкий

Дефекты

CWE-89