10

CVE-2002-1110

Multiple SQL injection vulnerabilities in Mantis 0.17.2 and earlier, when running without magic_quotes_gpc enabled, allows remote attackers to gain privileges or perform unauthorized database operations via modified form fields, e.g. to account_update.php.

Data is provided by the National Vulnerability Database (NVD)
MantisMantis Version0.15.3
MantisMantis Version0.15.4
MantisMantis Version0.15.5
MantisMantis Version0.15.6
MantisMantis Version0.15.7
MantisMantis Version0.15.8
MantisMantis Version0.15.9
MantisMantis Version0.15.10
MantisMantis Version0.15.11
MantisMantis Version0.15.12
MantisMantis Version0.16.0
MantisMantis Version0.16.1
MantisMantis Version0.17.0
MantisMantis Version0.17.1
MantisMantis Version0.17.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.53% 0.645
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C