Lucene search

K
nvd[email protected]NVD:CVE-2014-6387
HistoryOct 22, 2014 - 2:55 p.m.

CVE-2014-6387

2014-10-2214:55:06
CWE-287
web.nvd.nist.gov
6

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

6.6

Confidence

Low

EPSS

0.004

Percentile

72.8%

gpc_api.php in MantisBT 1.2.17 and earlier allows remote attackers to bypass authenticated via a password starting will a null byte, which triggers an unauthenticated bind.

Affected configurations

Nvd
Node
mantisbtmantisbtRange1.2.17
OR
mantisbtmantisbtMatch1.2.0
OR
mantisbtmantisbtMatch1.2.0alpha1
OR
mantisbtmantisbtMatch1.2.0alpha2
OR
mantisbtmantisbtMatch1.2.0alpha3
OR
mantisbtmantisbtMatch1.2.0rc1
OR
mantisbtmantisbtMatch1.2.0rc2
OR
mantisbtmantisbtMatch1.2.1
OR
mantisbtmantisbtMatch1.2.2
OR
mantisbtmantisbtMatch1.2.3
OR
mantisbtmantisbtMatch1.2.4
OR
mantisbtmantisbtMatch1.2.5
OR
mantisbtmantisbtMatch1.2.6
OR
mantisbtmantisbtMatch1.2.7
OR
mantisbtmantisbtMatch1.2.8
OR
mantisbtmantisbtMatch1.2.9
OR
mantisbtmantisbtMatch1.2.10
OR
mantisbtmantisbtMatch1.2.11
OR
mantisbtmantisbtMatch1.2.12
OR
mantisbtmantisbtMatch1.2.13
OR
mantisbtmantisbtMatch1.2.14
OR
mantisbtmantisbtMatch1.2.15
OR
mantisbtmantisbtMatch1.2.16
VendorProductVersionCPE
mantisbtmantisbt*cpe:2.3:a:mantisbt:mantisbt:*:*:*:*:*:*:*:*
mantisbtmantisbt1.2.0cpe:2.3:a:mantisbt:mantisbt:1.2.0:*:*:*:*:*:*:*
mantisbtmantisbt1.2.0cpe:2.3:a:mantisbt:mantisbt:1.2.0:alpha1:*:*:*:*:*:*
mantisbtmantisbt1.2.0cpe:2.3:a:mantisbt:mantisbt:1.2.0:alpha2:*:*:*:*:*:*
mantisbtmantisbt1.2.0cpe:2.3:a:mantisbt:mantisbt:1.2.0:alpha3:*:*:*:*:*:*
mantisbtmantisbt1.2.0cpe:2.3:a:mantisbt:mantisbt:1.2.0:rc1:*:*:*:*:*:*
mantisbtmantisbt1.2.0cpe:2.3:a:mantisbt:mantisbt:1.2.0:rc2:*:*:*:*:*:*
mantisbtmantisbt1.2.1cpe:2.3:a:mantisbt:mantisbt:1.2.1:*:*:*:*:*:*:*
mantisbtmantisbt1.2.2cpe:2.3:a:mantisbt:mantisbt:1.2.2:*:*:*:*:*:*:*
mantisbtmantisbt1.2.3cpe:2.3:a:mantisbt:mantisbt:1.2.3:*:*:*:*:*:*:*
Rows per page:
1-10 of 231

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

6.6

Confidence

Low

EPSS

0.004

Percentile

72.8%