Vulnerabilities
Vulnerable Software
Mantisbt:  >> Mantisbt  >> 1.2.16  Security Vulnerabilities
gpc_api.php in MantisBT 1.2.17 and earlier allows remote attackers to bypass authenticated via a password starting will a null byte, which triggers an unauthenticated bind.
CVSS Score
5.0
EPSS Score
0.003
Published
2014-10-22
SQL injection vulnerability in the manage configuration page (adm_config_report.php) in MantisBT 1.2.13 through 1.2.16 allows remote authenticated administrators to execute arbitrary SQL commands via the filter_config_id parameter.
CVSS Score
6.5
EPSS Score
0.454
Published
2014-03-05


Contact Us

Shodan ® - All rights reserved