Vulnerability Name:

CVE-2006-6574 (CCN-30870)

Assigned:2006-12-13
Published:2006-12-13
Updated:2017-07-29
Summary:Mantis before 1.1.0a2 does not implement per-item access control for Issue History (Bug History), which allows remote attackers to obtain sensitive information by reading the Change column, as demonstrated by the Change column of a custom field.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-Other
Vulnerability Consequences:Obtain Information
References:Source: MISC
Type: UNKNOWN
http://bugs.mantisbugtracker.com/view.php?id=3375

Source: MISC
Type: UNKNOWN
http://bugs.mantisbugtracker.com/view.php?id=7364

Source: MITRE
Type: CNA
CVE-2006-6574

Source: MISC
Type: UNKNOWN
http://mantisbt.cvs.sourceforge.net/mantisbt/mantisbt/core/history_api.php?r1=1.34&r2=1.35

Source: MISC
Type: UNKNOWN
http://mantisbt.cvs.sourceforge.net/mantisbt/mantisbt/core/history_api.php?view=log

Source: CCN
Type: SA23258
Mantis Custom Field Information Disclosure

Source: SECUNIA
Type: Vendor Advisory
23258

Source: SECUNIA
Type: UNKNOWN
28551

Source: CCN
Type: SourceForge.net: Files
Mantis - File Release Notes and Changelog - Release Name: 1.1.0a2

Source: CONFIRM
Type: Patch
http://sourceforge.net/project/shownotes.php?release_id=469627

Source: DEBIAN
Type: UNKNOWN
DSA-1467

Source: DEBIAN
Type: DSA-1467
mantis -- several vulnerabilities

Source: CCN
Type: Mantis Download Web Page
Mantis

Source: CONFIRM
Type: UNKNOWN
http://www.mantisbugtracker.com/changelog.php

Source: CCN
Type: OSVDB ID: 32195
Mantis Issue History Custom Field Information Disclosure

Source: BID
Type: UNKNOWN
21566

Source: CCN
Type: BID-21566
Mantis Custom Fields Information Disclosure Vulnerability

Source: VUPEN
Type: UNKNOWN
ADV-2006-4978

Source: XF
Type: UNKNOWN
mantis-customfield-info-disclosure(30870)

Source: XF
Type: UNKNOWN
mantis-customfield-info-disclosure(30870)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:mantis:mantis:1.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:mantis:mantis:1.0.0_rc1:*:*:*:*:*:*:*
  • OR cpe:/a:mantis:mantis:1.0.0_rc2:*:*:*:*:*:*:*
  • OR cpe:/a:mantis:mantis:1.0.0_rc3:*:*:*:*:*:*:*
  • OR cpe:/a:mantis:mantis:1.0.0_rc4:*:*:*:*:*:*:*
  • OR cpe:/a:mantis:mantis:1.0.0_rc5:*:*:*:*:*:*:*
  • OR cpe:/a:mantis:mantis:1.0.0a1:*:*:*:*:*:*:*
  • OR cpe:/a:mantis:mantis:1.0.0a2:*:*:*:*:*:*:*
  • OR cpe:/a:mantis:mantis:1.0.0a3:*:*:*:*:*:*:*
  • OR cpe:/a:mantis:mantis:1.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:mantis:mantis:1.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:mantis:mantis:1.0.3:*:*:*:*:*:*:*
  • OR cpe:/a:mantis:mantis:1.0.4:*:*:*:*:*:*:*
  • OR cpe:/a:mantis:mantis:1.0.5:*:*:*:*:*:*:*
  • OR cpe:/a:mantis:mantis:1.0.6:*:*:*:*:*:*:*
  • OR cpe:/a:mantis:mantis:*:*:*:*:*:*:*:* (Version <= 1.1.0a1)

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:7408
    P
    DSA-1467 mantis -- several vulnerabilities
    2014-06-23
    oval:org.debian:def:1467
    V
    several vulnerabilities
    2008-01-19
    BACK
    mantis mantis 1.0.0
    mantis mantis 1.0.0_rc1
    mantis mantis 1.0.0_rc2
    mantis mantis 1.0.0_rc3
    mantis mantis 1.0.0_rc4
    mantis mantis 1.0.0_rc5
    mantis mantis 1.0.0a1
    mantis mantis 1.0.0a2
    mantis mantis 1.0.0a3
    mantis mantis 1.0.1
    mantis mantis 1.0.2
    mantis mantis 1.0.3
    mantis mantis 1.0.4
    mantis mantis 1.0.5
    mantis mantis 1.0.6
    mantis mantis *