Логотип exploitDog
bind:CVE-2017-12419
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2017-12419

Количество 3

Количество 3

nvd логотип

CVE-2017-12419

около 8 лет назад

If, after successful installation of MantisBT through 2.5.2 on MySQL/MariaDB, the administrator does not remove the 'admin' directory (as recommended in the "Post-installation and upgrade tasks" section of the MantisBT Admin Guide), and the MySQL client has a local_infile setting enabled (in php.ini mysqli.allow_local_infile, or the MySQL client config file, depending on the PHP setup), an attacker may take advantage of MySQL's "connect file read" feature to remotely access files on the MantisBT server.

CVSS3: 4.9
EPSS: Низкий
debian логотип

CVE-2017-12419

около 8 лет назад

If, after successful installation of MantisBT through 2.5.2 on MySQL/M ...

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-h6vg-jrj8-p6w5

больше 3 лет назад

If, after successful installation of MantisBT through 2.5.2 on MySQL/MariaDB, the administrator does not remove the 'admin' directory (as recommended in the "Post-installation and upgrade tasks" section of the MantisBT Admin Guide), and the MySQL client has a local_infile setting enabled (in php.ini mysqli.allow_local_infile, or the MySQL client config file, depending on the PHP setup), an attacker may take advantage of MySQL's "connect file read" feature to remotely access files on the MantisBT server.

CVSS3: 4.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2017-12419

If, after successful installation of MantisBT through 2.5.2 on MySQL/MariaDB, the administrator does not remove the 'admin' directory (as recommended in the "Post-installation and upgrade tasks" section of the MantisBT Admin Guide), and the MySQL client has a local_infile setting enabled (in php.ini mysqli.allow_local_infile, or the MySQL client config file, depending on the PHP setup), an attacker may take advantage of MySQL's "connect file read" feature to remotely access files on the MantisBT server.

CVSS3: 4.9
1%
Низкий
около 8 лет назад
debian логотип
CVE-2017-12419

If, after successful installation of MantisBT through 2.5.2 on MySQL/M ...

CVSS3: 4.9
1%
Низкий
около 8 лет назад
github логотип
GHSA-h6vg-jrj8-p6w5

If, after successful installation of MantisBT through 2.5.2 on MySQL/MariaDB, the administrator does not remove the 'admin' directory (as recommended in the "Post-installation and upgrade tasks" section of the MantisBT Admin Guide), and the MySQL client has a local_infile setting enabled (in php.ini mysqli.allow_local_infile, or the MySQL client config file, depending on the PHP setup), an attacker may take advantage of MySQL's "connect file read" feature to remotely access files on the MantisBT server.

CVSS3: 4.9
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу