|
Mantis 'account_prefs_update.php' Local File Include Vulnerability
Mantis is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input. An attacker can exploit this vulnerability using directory-traversal strings to view files and execute local scripts in the context of the webserver process. This may aid in further attacks. Versions prior to Mantis 1.1.2 are vulnerable. |
|
|
Privacy Statement |