Core Security
info@coresecurity.com  | +1.617.399.6980 | Contact Us   Core Blog Core Blog Twitter LinkedIn youtube
SHARE

CORE IMPACT v8 - Exploits Update (Wed Feb 18 2009)

Mantis Manage_proj_page Remote Code Execution

Exploits/Remote  [Linux]




• Wed Feb 18 2009
This module exploits a Remote Code Execution vulnerability in Mantis version 1.1.3 caused by Mantis handling the sort parameter in manage_proj_page without the proper validation. This allows for remote code execution on Mantis' Web server.

Exploits Vulnerabiltiy: CVE-2008-4687



< Back to Product Updates