Lucene search

K
archlinuxArch LinuxASA-201411-3
HistoryNov 05, 2014 - 12:00 a.m.

mantisbt: sql injection

2014-11-0500:00:00
Arch Linux
lists.archlinux.org
25

EPSS

0.007

Percentile

79.7%

Edwin Gozeling and Wim Visser discovered that when the project_id
parameter of the SOAP-request starts with the integer of a project to
which the user (or anonymous) is authorized, the ENTIRE value will
become the first item of $t_projects. As this value is concatenated in
the SQL statement, SQL-injection becomes possible.

OSVersionArchitecturePackageVersionFilename
anyanyanymantisbt< 1.2.17-3UNKNOWN