Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2008-4687

Опубликовано: 22 окт. 2008
Источник: ubuntu
Приоритет: low
EPSS Высокий
CVSS2: 9

Описание

manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort parameter containing PHP sequences, which are processed by create_function within the multi_sort function in core/utility_api.php.

РелизСтатусПримечание
dapper

ignored

end of life
devel

not-affected

1.1.6+dfsg-2
gutsy

ignored

end of life, was needed
hardy

ignored

end of life
intrepid

ignored

end of life, was needed
jaunty

not-affected

1.1.6+dfsg-2
karmic

not-affected

1.1.6+dfsg-2
lucid

not-affected

1.1.6+dfsg-2
maverick

not-affected

1.1.6+dfsg-2
natty

not-affected

1.1.6+dfsg-2

Показывать по

Ссылки на источники

EPSS

Процентиль: 99%
0.79225
Высокий

9 Critical

CVSS2

Связанные уязвимости

nvd
больше 17 лет назад

manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort parameter containing PHP sequences, which are processed by create_function within the multi_sort function in core/utility_api.php.

debian
больше 17 лет назад

manage_proj_page.php in Mantis before 1.1.4 allows remote authenticate ...

github
больше 3 лет назад

manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort parameter containing PHP sequences, which are processed by create_function within the multi_sort function in core/utility_api.php.

EPSS

Процентиль: 99%
0.79225
Высокий

9 Critical

CVSS2