CVE-2014-8598

Scores

EPSS

0.674medium67.4%
0%20%40%60%80%100%

Percentile: 67.4%

CVSS

6.4medium2.0
0246810

CVSS Score: 6.4/10

All CVSS Scores

CVSS 2.0
6.4

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Description

The XML Import/Export plugin in MantisBT 1.2.x does not restrict access, which allows remote attackers to (1) upload arbitrary XML files via the import page or (2) obtain sensitive information via the export page. NOTE: this issue can be combined with CVE-2014-7146 to execute arbitrary PHP code.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

debiannvd

CWEs

CWE-19

Exploits

Exploit ID: 41685

Source: exploitdb

URL: https://www.exploit-db.com/exploits/41685

Vulnerable Software (3)

Type: Configuration

Product: mantis

Operating System: debian

Trait:
{  "unfixed": true}

Source: debian

Type: Configuration

Product: mantis

Operating System: debian squeeze 6

Trait:
{  "unfixed": true}

Source: debian

Type: Configuration

Vendor: *

Product: mantisbt

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:mantisbt:mantisbt:*:*:*:*:*:*:*:*",      "versionEndIncluding": "1.2.17",      "vulnerable": true    }  ],  "operator": "OR"}

Source: nvd

End of list