Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2012-2692

Опубликовано: 17 июн. 2012
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 3.6

Описание

MantisBT before 1.2.11 does not check the delete_attachments_threshold permission when form_security_validation is set to OFF, which allows remote authenticated users with certain privileges to bypass intended access restrictions and delete arbitrary attachments.

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

DNE

hardy

ignored

end of life
lucid

ignored

end of life
natty

released

1.1.8+dfsg-10squeeze2build0.11.04.1
oneiric

ignored

end of life
precise

ignored

end of life
precise/esm

DNE

precise was needed
quantal

not-affected

1.2.11-1
raring

not-affected

1.2.11-1

Показывать по

EPSS

Процентиль: 71%
0.0066
Низкий

3.6 Low

CVSS2

Связанные уязвимости

nvd
больше 13 лет назад

MantisBT before 1.2.11 does not check the delete_attachments_threshold permission when form_security_validation is set to OFF, which allows remote authenticated users with certain privileges to bypass intended access restrictions and delete arbitrary attachments.

debian
больше 13 лет назад

MantisBT before 1.2.11 does not check the delete_attachments_threshold ...

github
больше 3 лет назад

MantisBT before 1.2.11 does not check the delete_attachments_threshold permission when form_security_validation is set to OFF, which allows remote authenticated users with certain privileges to bypass intended access restrictions and delete arbitrary attachments.

EPSS

Процентиль: 71%
0.0066
Низкий

3.6 Low

CVSS2