Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2012-1120

Опубликовано: 29 июн. 2012
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 3.6

Описание

The SOAP API in MantisBT before 1.2.9 does not properly enforce the bugnote_allow_user_edit_delete and delete_bug_threshold permissions, which allows remote authenticated users with read and write SOAP API privileges to delete arbitrary bug reports and bug notes.

РелизСтатусПримечание
devel

DNE

hardy

ignored

end of life
lucid

ignored

end of life
maverick

ignored

end of life
natty

released

1.1.8+dfsg-10squeeze2build0.11.04.1
oneiric

ignored

end of life
precise

not-affected

1.2.10-1
quantal

not-affected

1.2.10-1
raring

not-affected

1.2.10-1
saucy

not-affected

1.2.10-1

Показывать по

Ссылки на источники

EPSS

Процентиль: 75%
0.00902
Низкий

3.6 Low

CVSS2

Связанные уязвимости

nvd
больше 13 лет назад

The SOAP API in MantisBT before 1.2.9 does not properly enforce the bugnote_allow_user_edit_delete and delete_bug_threshold permissions, which allows remote authenticated users with read and write SOAP API privileges to delete arbitrary bug reports and bug notes.

debian
больше 13 лет назад

The SOAP API in MantisBT before 1.2.9 does not properly enforce the bu ...

github
больше 3 лет назад

The SOAP API in MantisBT before 1.2.9 does not properly enforce the bugnote_allow_user_edit_delete and delete_bug_threshold permissions, which allows remote authenticated users with read and write SOAP API privileges to delete arbitrary bug reports and bug notes.

EPSS

Процентиль: 75%
0.00902
Низкий

3.6 Low

CVSS2