7.5

CVE-2002-1113

Exploit

summary_graph_functions.php in Mantis 0.17.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the g_jpgraph_path parameter to reference the location of the PHP code.

Data is provided by the National Vulnerability Database (NVD)
MantisMantis Version0.15.3
MantisMantis Version0.15.4
MantisMantis Version0.15.5
MantisMantis Version0.15.6
MantisMantis Version0.15.7
MantisMantis Version0.15.8
MantisMantis Version0.15.9
MantisMantis Version0.15.10
MantisMantis Version0.15.11
MantisMantis Version0.15.12
MantisMantis Version0.16.0
MantisMantis Version0.16.1
MantisMantis Version0.17.0
MantisMantis Version0.17.1
MantisMantis Version0.17.2
MantisMantis Version0.17.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 13.87% 0.94
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P