CVE-2002-1111: Medium severity Mantis Mantis vulnerability
Published Oct 4, 2002
·Updated
printallbugpage.php in Mantis 0.17.3 and earlier does not verify the limitreporters option, which allows remote attackers to view bug summaries for bugs that would otherwise be restricted.
Affected Software
6 affected components
Mantis Mantis=0.17.0
Mantis Mantis=0.16.1
Mantis Mantis=0.17.2
Mantis Mantis=0.17.3
Mantis Mantis=0.17.1
Mantis Mantis=0.16.0
Remediation
Patch Available
Patch Available
Event History
Oct 4, 2002
CVE Published
04:00 AM
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1111?
CVE-2002-1111 is classified as a medium severity vulnerability due to its ability to expose restricted bug summaries.
2
How do I fix CVE-2002-1111?
To fix CVE-2002-1111, upgrade Mantis to version 0.17.4 or later which addresses the vulnerability.
3
What versions of Mantis are affected by CVE-2002-1111?
CVE-2002-1111 affects Mantis versions 0.16.0 through 0.17.3.
4
Can CVE-2002-1111 lead to unauthorized access?
Yes, CVE-2002-1111 can allow remote attackers to view bug summaries that should be restricted, leading to unauthorized access.
5
What component of Mantis is impacted by CVE-2002-1111?
CVE-2002-1111 impacts the print_all_bug_page.php component of Mantis.