Lucene search

K
nvd[email protected]NVD:CVE-2014-1608
HistoryMar 18, 2014 - 5:03 p.m.

CVE-2014-1608

2014-03-1817:03:00
CWE-89
web.nvd.nist.gov
7

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.9

Confidence

Low

EPSS

0.009

Percentile

83.0%

SQL injection vulnerability in the mci_file_get function in api/soap/mc_file_api.php in MantisBT before 1.2.16 allows remote attackers to execute arbitrary SQL commands via a crafted envelope tag in a mc_issue_attachment_get SOAP request.

Affected configurations

Nvd
Node
mantisbtmantisbtRange1.2.15
OR
mantisbtmantisbtMatch1.2.0
OR
mantisbtmantisbtMatch1.2.0alpha1
OR
mantisbtmantisbtMatch1.2.0alpha2
OR
mantisbtmantisbtMatch1.2.0alpha3
OR
mantisbtmantisbtMatch1.2.0rc1
OR
mantisbtmantisbtMatch1.2.0rc2
OR
mantisbtmantisbtMatch1.2.1
OR
mantisbtmantisbtMatch1.2.2
OR
mantisbtmantisbtMatch1.2.3
OR
mantisbtmantisbtMatch1.2.4
OR
mantisbtmantisbtMatch1.2.5
OR
mantisbtmantisbtMatch1.2.6
OR
mantisbtmantisbtMatch1.2.7
OR
mantisbtmantisbtMatch1.2.8
OR
mantisbtmantisbtMatch1.2.9
OR
mantisbtmantisbtMatch1.2.10
OR
mantisbtmantisbtMatch1.2.11
OR
mantisbtmantisbtMatch1.2.13
OR
mantisbtmantisbtMatch1.2.14
Node
debiandebian_linuxMatch7.0
VendorProductVersionCPE
mantisbtmantisbt*cpe:2.3:a:mantisbt:mantisbt:*:*:*:*:*:*:*:*
mantisbtmantisbt1.2.0cpe:2.3:a:mantisbt:mantisbt:1.2.0:*:*:*:*:*:*:*
mantisbtmantisbt1.2.0cpe:2.3:a:mantisbt:mantisbt:1.2.0:alpha1:*:*:*:*:*:*
mantisbtmantisbt1.2.0cpe:2.3:a:mantisbt:mantisbt:1.2.0:alpha2:*:*:*:*:*:*
mantisbtmantisbt1.2.0cpe:2.3:a:mantisbt:mantisbt:1.2.0:alpha3:*:*:*:*:*:*
mantisbtmantisbt1.2.0cpe:2.3:a:mantisbt:mantisbt:1.2.0:rc1:*:*:*:*:*:*
mantisbtmantisbt1.2.0cpe:2.3:a:mantisbt:mantisbt:1.2.0:rc2:*:*:*:*:*:*
mantisbtmantisbt1.2.1cpe:2.3:a:mantisbt:mantisbt:1.2.1:*:*:*:*:*:*:*
mantisbtmantisbt1.2.2cpe:2.3:a:mantisbt:mantisbt:1.2.2:*:*:*:*:*:*:*
mantisbtmantisbt1.2.3cpe:2.3:a:mantisbt:mantisbt:1.2.3:*:*:*:*:*:*:*
Rows per page:
1-10 of 211

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.9

Confidence

Low

EPSS

0.009

Percentile

83.0%