| Vulnerability Name: | CVE-2014-9572 (CCN-100211) | ||||||||
| Assigned: | 2015-01-17 | ||||||||
| Published: | 2015-01-17 | ||||||||
| Updated: | 2017-09-08 | ||||||||
| Summary: | MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 does not properly restrict access to /*/install.php, which allows remote attackers to obtain database credentials via the install parameter with the value 4. | ||||||||
| CVSS v3 Severity: | 6.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
| ||||||||
| CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
4.7 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-284 | ||||||||
| Vulnerability Consequences: | Bypass Security | ||||||||
| References: | Source: MITRE Type: CNA CVE-2014-9572 Source: CCN Type: oss-security Mailing List, Sat, 17 Jan 2015 01:01:55 +0100 CVE-2014-9572: Improper Access Control in install.php Source: MLIST Type: UNKNOWN [oss-security] 20150117 CVE-2014-9572: Improper Access Control in install.php Source: CCN Type: oss-security Mailing List, Sat, 17 Jan 2015 01:08:31 +0100 CVE-2014-9571, -9572 and -9573 affect MantisBT Source: CCN Type: SECTRACK ID: 1031633 MantisBT Bugs Permit Remote Cross-Site Scripting, SQL Injection, and Security Bypass Attacks Source: SECTRACK Type: UNKNOWN 1031633 Source: XF Type: UNKNOWN mantisbt-cve20149572-sec-bypass(100211) Source: XF Type: UNKNOWN mantisbt-cve20149572-sec-bypass(100211) Source: CCN Type: Packet Storm Security [01-29-2015] MantisBT 1.2.17 XSS / Improper Access Control / SQL Injection Source: MISC Type: UNKNOWN https://www.htbridge.com/advisory/HTB23243 Source: CCN Type: MantisBT Web site Mantis Bug Tracker Source: CONFIRM Type: UNKNOWN https://www.mantisbt.org/bugs/view.php?id=17937 Source: CONFIRM Type: Vendor Advisory https://www.mantisbt.org/bugs/view.php?id=17939 Source: CCN Type: WhiteSource Vulnerability Database CVE-2014-9572 | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| Oval Definitions | |||||||||
| |||||||||
| BACK | |||||||||