Lucene search

K
freebsdFreeBSD82A41084-6CE7-11DA-B90C-000E0C2E438A
HistoryOct 26, 2005 - 12:00 a.m.

mantis -- "t_core_path" file inclusion vulnerability

2005-10-2600:00:00
vuxml.freebsd.org
20

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.108

Percentile

95.1%

Secunia Research reports:

Input passed to the “t_core_path” parameter in
“bug_sponsorship_list_view_inc.php” isn’t properly verified,
before it used to include files. This can be exploited to
include arbitrary files from external and local
resources.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchmantis< 1.0.0rc3UNKNOWN

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.108

Percentile

95.1%

Related for 82A41084-6CE7-11DA-B90C-000E0C2E438A