CVE-2004-1734: High severity Mantis Mantis vulnerability
PHP remote file inclusion vulnerability in Mantis 0.19.0a allows remote attackers to execute arbitrary PHP code by modifying the (1) tcorepath parameter to bugapi.php or (2) tcoredir parameter to relationshipapi.php to reference a URL on a remote web server that contains the code.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1734?
The severity of CVE-2004-1734 is classified as high due to the potential for remote code execution.
How do I fix CVE-2004-1734?
To fix CVE-2004-1734, update Mantis to a version later than 0.19.0a that has addressed this vulnerability.
What type of vulnerability is CVE-2004-1734?
CVE-2004-1734 is a remote file inclusion vulnerability affecting Mantis 0.19.0a.
What components are affected by CVE-2004-1734?
CVE-2004-1734 affects the bug_api.php and relationship_api.php components of Mantis 0.19.0a.
Can CVE-2004-1734 be exploited remotely?
Yes, CVE-2004-1734 can be exploited remotely by attackers who modify specific parameters to execute arbitrary PHP code.