gpc_api.php in MantisBT 1.2.17 and earlier allows remote attackers to bypass authenticated via a password starting will a null byte, which triggers an unauthenticated bind.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2014-6271
http://www.openwall.com/lists/oss-security/2014/09/13/1
http://www.openwall.com/lists/oss-security/2014/09/12/14