Remote arbitrary code execution vulnerability in mantis
| Package(s): | mantis | CVE #(s): | |||||
| Created: | August 14, 2002 | Updated: | August 20, 2002 | ||||
| Description: | Mantis is a php based bug tracking system.
Joao Gouveia and the Debian Security Team found
multiple insecure uses of uninitialized variables in mantis.
When these occasions are exploited, a remote user is able
to execute arbitrary code under the webserver user id on the web
server hosting the mantis system.
| ||||||
| Alerts: |
| ||||||
