Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Mantis Unauthorized Bug Viewing Vulnerability

Mantis is a web-based bug tracking system. It is written in PHP and back-ended by a MySQL database.

A number of scripts used to view bug data do not check user permissions. Users may directly call these scripts, and specify arbitrary bug IDs through CGI parameters. Details of these bugs will then be displayed to the user.







 

Privacy Statement
Copyright 2008, SecurityFocus