Vulnerabilities > CVE-2006-6574 - Information Disclosure vulnerability in Mantis Custom Fields
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
NONE Availability impact
NONE Summary
Mantis before 1.1.0a2 does not implement per-item access control for Issue History (Bug History), which allows remote attackers to obtain sensitive information by reading the Change column, as demonstrated by the Change column of a custom field.
Vulnerable Configurations
Nessus
NASL family | Debian Local Security Checks |
NASL id | DEBIAN_DSA-1467.NASL |
description | Several remote vulnerabilities have been discovered in Mantis, a web-based bug tracking system. The Common Vulnerabilities and Exposures project identifies the following problems : - CVE-2006-6574 Custom fields were not appropriately protected by per-item access control, allowing for sensitive data to be published. - CVE-2007-6611 Multiple cross site scripting issues allowed a remote attacker to insert malicious HTML or web script into Mantis web pages. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 30023 |
published | 2008-01-21 |
reporter | This script is Copyright (C) 2008-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/30023 |
title | Debian DSA-1467-1 : mantis - several vulnerabilities |
code |
|
References
- http://bugs.mantisbugtracker.com/view.php?id=3375
- http://bugs.mantisbugtracker.com/view.php?id=7364
- http://mantisbt.cvs.sourceforge.net/mantisbt/mantisbt/core/history_api.php?r1=1.34&r2=1.35
- http://mantisbt.cvs.sourceforge.net/mantisbt/mantisbt/core/history_api.php?view=log
- http://secunia.com/advisories/23258
- http://secunia.com/advisories/28551
- http://sourceforge.net/project/shownotes.php?release_id=469627
- http://www.debian.org/security/2008/dsa-1467
- http://www.mantisbugtracker.com/changelog.php
- http://www.securityfocus.com/bid/21566
- http://www.vupen.com/english/advisories/2006/4978
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30870