Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-735c-hjfp-pf6m

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The print_test_result function in admin/upgrade_unattended.php in MantisBT 1.1.0a3 through 1.2.x before 1.2.18 allows remote attackers to obtain database credentials via a URL in the hostname parameter and reading the parameters in the response sent to the URL.

The print_test_result function in admin/upgrade_unattended.php in MantisBT 1.1.0a3 through 1.2.x before 1.2.18 allows remote attackers to obtain database credentials via a URL in the hostname parameter and reading the parameters in the response sent to the URL.

EPSS

Процентиль: 64%
0.00472
Низкий

Дефекты

CWE-200

Связанные уязвимости

ubuntu
около 11 лет назад

The print_test_result function in admin/upgrade_unattended.php in MantisBT 1.1.0a3 through 1.2.x before 1.2.18 allows remote attackers to obtain database credentials via a URL in the hostname parameter and reading the parameters in the response sent to the URL.

nvd
около 11 лет назад

The print_test_result function in admin/upgrade_unattended.php in MantisBT 1.1.0a3 through 1.2.x before 1.2.18 allows remote attackers to obtain database credentials via a URL in the hostname parameter and reading the parameters in the response sent to the URL.

debian
около 11 лет назад

The print_test_result function in admin/upgrade_unattended.php in Mant ...

EPSS

Процентиль: 64%
0.00472
Низкий

Дефекты

CWE-200