mirror of
https://github.com/0xMarcio/cve.git
synced 2026-06-05 06:38:06 +02:00
846 B
846 B
CVE-2008-3333
Description
Directory traversal vulnerability in core/lang_api.php in Mantis before 1.1.2 allows remote attackers to include and execute arbitrary files via the language parameter to the user preferences page (account_prefs_update.php).
POC
Reference
- http://www.mantisbt.org/bugs/view.php?id=9154
- http://www.mantisbt.org/bugs/view.php?id=9154
- https://bugzilla.redhat.com/show_bug.cgi?id=456044
- https://bugzilla.redhat.com/show_bug.cgi?id=456044
Github
No PoCs found on GitHub currently.