Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2012-2691

Опубликовано: 17 июн. 2012
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 7.5

Описание

The mc_issue_note_update function in the SOAP API in MantisBT before 1.2.11 does not properly check privileges, which allows remote attackers with bug reporting privileges to edit arbitrary bugnotes via a SOAP request.

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

DNE

hardy

ignored

end of life
lucid

ignored

end of life
natty

released

1.1.8+dfsg-10squeeze2build0.11.04.1
oneiric

ignored

end of life
precise

ignored

end of life
precise/esm

DNE

precise was needed
quantal

not-affected

1.2.11-1
raring

not-affected

1.2.11-1

Показывать по

EPSS

Процентиль: 88%
0.03724
Низкий

7.5 High

CVSS2

Связанные уязвимости

nvd
больше 13 лет назад

The mc_issue_note_update function in the SOAP API in MantisBT before 1.2.11 does not properly check privileges, which allows remote attackers with bug reporting privileges to edit arbitrary bugnotes via a SOAP request.

debian
больше 13 лет назад

The mc_issue_note_update function in the SOAP API in MantisBT before 1 ...

github
больше 3 лет назад

The mc_issue_note_update function in the SOAP API in MantisBT before 1.2.11 does not properly check privileges, which allows remote attackers with bug reporting privileges to edit arbitrary bugnotes via a SOAP request.

EPSS

Процентиль: 88%
0.03724
Низкий

7.5 High

CVSS2