CVE-2002-1114: High severity mantis mantis vulnerability
Published Sep 10, 2002
·Updated
configinc2.php in Mantis before 0.17.4 allows remote attackers to execute arbitrary code or read arbitrary files via the parameters (1) gbottomincludepage, (2) gtopincludepage, (3) gcssincludefile, (4) gmetaincludefile, or (5) a cookie.
Affected Software
4 affected components
Mantis Mantis=0.17.0
Mantis Mantis=0.17.1
Mantis Mantis=0.17.2
Mantis Mantis=0.17.3
Remediation
Patch Available
Event History
Sep 10, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1114?
CVE-2002-1114 is considered critical due to its potential to allow arbitrary code execution and unauthorized file access.
2
How do I fix CVE-2002-1114?
To mitigate CVE-2002-1114, upgrade Mantis to version 0.17.4 or later.
3
What versions of Mantis are affected by CVE-2002-1114?
CVE-2002-1114 affects Mantis versions 0.17.0 through 0.17.3.
4
Can I exploit CVE-2002-1114 without authentication?
Yes, CVE-2002-1114 can be exploited by remote attackers without requiring authentication.
5
What types of files can be accessed through CVE-2002-1114?
CVE-2002-1114 can potentially allow unauthorized access to arbitrary files on the server.