CVE-2005-3335

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

PHP file inclusion vulnerability in bug_sponsorship_list_view_inc.php in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbitrary PHP code and include arbitrary local files via the t_core_path parameter.

References

http://bugs.mantisbt.org/changelog_page.php

http://secunia.com/advisories/16506

http://secunia.com/advisories/16818

http://secunia.com/advisories/17362

http://secunia.com/advisories/17654

http://secunia.com/secunia_research/2005-46/advisory/

http://securityreason.com/securityalert/121

http://securitytracker.com/id?1015110

http://www.debian.org/security/2005/dsa-905

http://www.gentoo.org/security/en/glsa/glsa-200510-24.xml

http://www.securityfocus.com/bid/15212

http://www.securityfocus.com/bid/15227

http://www.vupen.com/english/advisories/2005/2221

https://exchange.xforce.ibmcloud.com/vulnerabilities/22886

Details

Source: MITRE

Published: 2005-10-27

Updated: 2017-07-11

Risk Information

CVSS v2

Base Score: 7.5

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 10

Severity: HIGH

Tenable Plugins

View all (5 total)

IDNameProductFamilySeverity
22771Debian DSA-905-1 : mantis - several vulnerabilitiesNessusDebian Local Security Checks
high
21458FreeBSD : mantis -- 't_core_path' file inclusion vulnerability (82a41084-6ce7-11da-b90c-000e0c2e438a)NessusFreeBSD Local Security Checks
high
20117GLSA-200510-24 : Mantis: Multiple vulnerabilitiesNessusGentoo Local Security Checks
high
20093Mantis < 0.19.3 Multiple VulnerabilitiesNessusCGI abuses
medium
3173Mantis < 0.19.3 Multiple Injection VulnerabilitiesNessus Network MonitorCGI
high