Vulnerability Name: | CVE-2006-6574 (CCN-30870) | ||||||||||||
Assigned: | 2006-12-13 | ||||||||||||
Published: | 2006-12-13 | ||||||||||||
Updated: | 2017-07-29 | ||||||||||||
Summary: | Mantis before 1.1.0a2 does not implement per-item access control for Issue History (Bug History), which allows remote attackers to obtain sensitive information by reading the Change column, as demonstrated by the Change column of a custom field. | ||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MISC Type: UNKNOWN http://bugs.mantisbugtracker.com/view.php?id=3375 Source: MISC Type: UNKNOWN http://bugs.mantisbugtracker.com/view.php?id=7364 Source: MITRE Type: CNA CVE-2006-6574 Source: MISC Type: UNKNOWN http://mantisbt.cvs.sourceforge.net/mantisbt/mantisbt/core/history_api.php?r1=1.34&r2=1.35 Source: MISC Type: UNKNOWN http://mantisbt.cvs.sourceforge.net/mantisbt/mantisbt/core/history_api.php?view=log Source: CCN Type: SA23258 Mantis Custom Field Information Disclosure Source: SECUNIA Type: Vendor Advisory 23258 Source: SECUNIA Type: UNKNOWN 28551 Source: CCN Type: SourceForge.net: Files Mantis - File Release Notes and Changelog - Release Name: 1.1.0a2 Source: CONFIRM Type: Patch http://sourceforge.net/project/shownotes.php?release_id=469627 Source: DEBIAN Type: UNKNOWN DSA-1467 Source: DEBIAN Type: DSA-1467 mantis -- several vulnerabilities Source: CCN Type: Mantis Download Web Page Mantis Source: CONFIRM Type: UNKNOWN http://www.mantisbugtracker.com/changelog.php Source: CCN Type: OSVDB ID: 32195 Mantis Issue History Custom Field Information Disclosure Source: BID Type: UNKNOWN 21566 Source: CCN Type: BID-21566 Mantis Custom Fields Information Disclosure Vulnerability Source: VUPEN Type: UNKNOWN ADV-2006-4978 Source: XF Type: UNKNOWN mantis-customfield-info-disclosure(30870) Source: XF Type: UNKNOWN mantis-customfield-info-disclosure(30870) | ||||||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |