Vulnerabilities > CVE-2006-6574 - Unspecified vulnerability in Mantis
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN mantis
nessus
Summary
Mantis before 1.1.0a2 does not implement per-item access control for Issue History (Bug History), which allows remote attackers to obtain sensitive information by reading the Change column, as demonstrated by the Change column of a custom field.
Vulnerable Configurations
Nessus
NASL family | Debian Local Security Checks |
NASL id | DEBIAN_DSA-1467.NASL |
description | Several remote vulnerabilities have been discovered in Mantis, a web-based bug tracking system. The Common Vulnerabilities and Exposures project identifies the following problems : - CVE-2006-6574 Custom fields were not appropriately protected by per-item access control, allowing for sensitive data to be published. - CVE-2007-6611 Multiple cross site scripting issues allowed a remote attacker to insert malicious HTML or web script into Mantis web pages. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 30023 |
published | 2008-01-21 |
reporter | This script is Copyright (C) 2008-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/30023 |
title | Debian DSA-1467-1 : mantis - several vulnerabilities |
code |
|
References
- http://bugs.mantisbugtracker.com/view.php?id=3375
- http://bugs.mantisbugtracker.com/view.php?id=3375
- http://bugs.mantisbugtracker.com/view.php?id=7364
- http://bugs.mantisbugtracker.com/view.php?id=7364
- http://mantisbt.cvs.sourceforge.net/mantisbt/mantisbt/core/history_api.php?r1=1.34&r2=1.35
- http://mantisbt.cvs.sourceforge.net/mantisbt/mantisbt/core/history_api.php?r1=1.34&r2=1.35
- http://mantisbt.cvs.sourceforge.net/mantisbt/mantisbt/core/history_api.php?view=log
- http://mantisbt.cvs.sourceforge.net/mantisbt/mantisbt/core/history_api.php?view=log
- http://secunia.com/advisories/23258
- http://secunia.com/advisories/23258
- http://secunia.com/advisories/28551
- http://secunia.com/advisories/28551
- http://sourceforge.net/project/shownotes.php?release_id=469627
- http://sourceforge.net/project/shownotes.php?release_id=469627
- http://www.debian.org/security/2008/dsa-1467
- http://www.debian.org/security/2008/dsa-1467
- http://www.mantisbugtracker.com/changelog.php
- http://www.mantisbugtracker.com/changelog.php
- http://www.securityfocus.com/bid/21566
- http://www.securityfocus.com/bid/21566
- http://www.vupen.com/english/advisories/2006/4978
- http://www.vupen.com/english/advisories/2006/4978
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30870
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30870