Mantis before 0.19.4 allows remote attackers to bypass the file upload size restriction by modifying the max_file_size parameter to (1) bug_file_add.php, (2) bug_report.php, (3) bug_report_advanced_page.php, and (4) proj_doc_add_page.php.
2005-12-28T01:03:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mantis | mantis | 0.10 | No |
Application | mantis | mantis | 0.10.0 | No |
Application | mantis | mantis | 0.10.1 | No |
Application | mantis | mantis | 0.10.2 | No |
Application | mantis | mantis | 0.11 | No |
Application | mantis | mantis | 0.11.0 | No |
Application | mantis | mantis | 0.11.1 | No |
Application | mantis | mantis | 0.12 | No |
Application | mantis | mantis | 0.12.0 | No |
Application | mantis | mantis | 0.13 | No |
Application | mantis | mantis | 0.13.0 | No |
Application | mantis | mantis | 0.13.1 | No |
Application | mantis | mantis | 0.14 | No |
Application | mantis | mantis | 0.14.0 | No |
Application | mantis | mantis | 0.14.1 | No |
Application | mantis | mantis | 0.14.2 | No |
Application | mantis | mantis | 0.14.3 | No |
Application | mantis | mantis | 0.14.4 | No |
Application | mantis | mantis | 0.14.5 | No |
Application | mantis | mantis | 0.14.6 | No |
Application | mantis | mantis | 0.14.7 | No |
Application | mantis | mantis | 0.14.8 | No |
Application | mantis | mantis | 0.15 | No |
Application | mantis | mantis | 0.15.0 | No |
Application | mantis | mantis | 0.15.1 | No |
Application | mantis | mantis | 0.15.2 | No |
Application | mantis | mantis | 0.16 | No |
Application | mantis | mantis | 0.16.0 | No |
Application | mantis | mantis | 0.17 | No |
Application | mantis | mantis | 0.17.0 | No |
Application | mantis | mantis | 0.17.4a | No |
Application | mantis | mantis | 0.18 | No |
Application | mantis | mantis | 0.18.0 | No |
Application | mantis | mantis | 0.18.0_rc1 | No |
Application | mantis | mantis | 0.18.0a1 | No |
Application | mantis | mantis | 0.18.0a2 | No |
Application | mantis | mantis | 0.18.0a3 | No |
Application | mantis | mantis | 0.18.0a4 | No |
Application | mantis | mantis | 0.18.1 | No |
Application | mantis | mantis | 0.18.2 | No |
Application | mantis | mantis | 0.18.3 | No |
Application | mantis | mantis | 0.18a1 | No |
Application | mantis | mantis | 0.19.0 | No |
Application | mantis | mantis | 0.19.0_rc1 | No |
Application | mantis | mantis | 0.19.0a | No |
Application | mantis | mantis | 0.19.0a1 | No |
Application | mantis | mantis | 0.19.0a2 | No |
Application | mantis | mantis | 0.19.1 | No |
Application | mantis | mantis | 0.19.2 | No |
Application | mantis | mantis | 0.19.3 | No |