CVE-2002-1113: High severity Mantis Mantis vulnerability
Published Oct 4, 2002
·Updated
summarygraphfunctions.php in Mantis 0.17.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the gjpgraphpath parameter to reference the location of the PHP code.
Affected Software
16 affected components
Mantis Mantis=0.15.12
Mantis Mantis=0.15.3
Mantis Mantis=0.15.9
Mantis Mantis=0.17.0
Mantis Mantis=0.15.10
Mantis Mantis=0.16.1
Mantis Mantis=0.15.4
Mantis Mantis=0.15.11
Mantis Mantis=0.17.2
Mantis Mantis=0.15.7
Mantis Mantis=0.17.3
Mantis Mantis=0.17.1
Mantis Mantis=0.15.5
Mantis Mantis=0.16.0
Mantis Mantis=0.15.8
Mantis Mantis=0.15.6
Remediation
Patch Available
Patch Available
Event History
Oct 4, 2002
CVE Published
04:00 AM
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1113?
CVE-2002-1113 is considered a critical vulnerability as it allows remote code execution.
2
How do I fix CVE-2002-1113?
To fix CVE-2002-1113, update to Mantis version 0.17.4 or later.
3
What software is affected by CVE-2002-1113?
CVE-2002-1113 affects Mantis versions up to and including 0.17.3.
4
Can CVE-2002-1113 be exploited remotely?
Yes, CVE-2002-1113 can be exploited remotely due to a flaw in the handling of the g_jpgraph_path parameter.
5
What impact does CVE-2002-1113 have on web applications?
CVE-2002-1113 can lead to arbitrary PHP code execution, compromising the security of affected web applications.