CVE-2005-3335: High severity Mantis Mantis vulnerability
Published Oct 27, 2005
·Updated
PHP file inclusion vulnerability in bugsponsorshiplistviewinc.php in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbitrary PHP code and include arbitrary local files via the tcorepath parameter.
Affected Software
2 affected components
Mantis Mantis=1.0.0_rc2
Mantis Mantis=0.19.2
Remediation
Patch Available
Patch Available
Patch Available
Event History
Oct 27, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-3335?
CVE-2005-3335 is considered a critical vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2005-3335?
To fix CVE-2005-3335, upgrade Mantis to version 1.0.0RC3 or later, or 0.19.3 or later.
3
What types of attacks can be executed due to CVE-2005-3335?
CVE-2005-3335 can be exploited to execute arbitrary PHP code, leading to potential full system compromise.
4
What versions of Mantis are affected by CVE-2005-3335?
CVE-2005-3335 affects Mantis versions 1.0.0RC2 and 0.19.2.
5
Is there a workaround for CVE-2005-3335 while waiting for a patch?
While waiting for a patch, restrict access to the affected files and parameters as a temporary workaround.