CVE-2002-1110: SQL Injection
Multiple SQL injection vulnerabilities in Mantis 0.17.2 and earlier, when running without magicquotesgpc enabled, allows remote attackers to gain privileges or perform unauthorized database operations via modified form fields, e.g. to accountupdate.php.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-1110?
CVE-2002-1110 has a high severity level due to the potential for remote attackers to gain unauthorized access or privileges.
How do I fix CVE-2002-1110?
To fix CVE-2002-1110, enable magic_quotes_gpc in your PHP configuration or upgrade to a patched version of Mantis.
Which versions of Mantis are affected by CVE-2002-1110?
CVE-2002-1110 affects Mantis version 0.17.2 and earlier, including 0.15.x versions.
What kind of attacks does CVE-2002-1110 enable?
CVE-2002-1110 enables SQL injection attacks that can lead to unauthorized database operations.
How can remote attackers exploit CVE-2002-1110?
Remote attackers can exploit CVE-2002-1110 by sending modified form fields to vulnerable Mantis installations.