CVE-2014-9280
Publication date 8 December 2014
Last updated 24 July 2024
Ubuntu priority
The current_user_get_bug_filter function in core/current_user_api.php in MantisBT before 1.2.18 allows remote attackers to execute arbitrary PHP code via the filter parameter.
Status
Package | Ubuntu Release | Status |
---|---|---|
mantis | ||
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
References
Other references
- http://github.com/mantisbt/mantisbt/commit/599364b2
- http://www.mantisbt.org/bugs/view.php?id=17875
- https://github.com/mantisbt/mantisbt/commit/599364b2
- http://xforce.iss.net/xforce/xfdb/99016
- http://seclists.org/oss-sec/2014/q4/923
- http://seclists.org/oss-sec/2014/q4/864
- https://www.cve.org/CVERecord?id=CVE-2014-9280