Lucene search

K
cveMitreCVE-2014-2238
HistoryMar 05, 2014 - 4:37 p.m.

CVE-2014-2238

2014-03-0516:37:41
CWE-89
mitre
web.nvd.nist.gov
34
cve-2014-2238
sql injection
mantisbt
adm_config_report.php
nvd

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

AI Score

6.5

Confidence

High

EPSS

0.005

Percentile

76.7%

SQL injection vulnerability in the manage configuration page (adm_config_report.php) in MantisBT 1.2.13 through 1.2.16 allows remote authenticated administrators to execute arbitrary SQL commands via the filter_config_id parameter.

Affected configurations

Nvd
Node
mantisbtmantisbtMatch1.2.13
OR
mantisbtmantisbtMatch1.2.14
OR
mantisbtmantisbtMatch1.2.15
OR
mantisbtmantisbtMatch1.2.16
VendorProductVersionCPE
mantisbtmantisbt1.2.13cpe:2.3:a:mantisbt:mantisbt:1.2.13:*:*:*:*:*:*:*
mantisbtmantisbt1.2.14cpe:2.3:a:mantisbt:mantisbt:1.2.14:*:*:*:*:*:*:*
mantisbtmantisbt1.2.15cpe:2.3:a:mantisbt:mantisbt:1.2.15:*:*:*:*:*:*:*
mantisbtmantisbt1.2.16cpe:2.3:a:mantisbt:mantisbt:1.2.16:*:*:*:*:*:*:*

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

AI Score

6.5

Confidence

High

EPSS

0.005

Percentile

76.7%