First published: Fri Nov 28 2014(Updated: )
Multiple SQL injection vulnerabilities in view_all_bug_page.php in MantisBT before 1.2.18 allow remote attackers to execute arbitrary SQL commands via the (1) sort or (2) dir parameter to view_all_set.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Debian | =1.2 | |
CentOS Libreport-plugin-mantisbt | <=1.2.17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-9089 is classified as a high severity vulnerability due to its ability to allow remote attackers to execute arbitrary SQL commands.
To fix CVE-2014-9089, upgrade MantisBT to version 1.2.18 or later.
CVE-2014-9089 affects MantisBT versions prior to 1.2.18.
Yes, CVE-2014-9089 can be exploited by remote attackers without requiring authentication.
The vulnerable parameters in CVE-2014-9089 are 'sort' and 'dir' in the view_all_bug_page.php.