mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-09 19:17:37 +02:00
852 B
852 B
CVE-2011-3357
Description
Directory traversal vulnerability in bug_actiongroup_ext_page.php in MantisBT before 1.2.8 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the action parameter, related to bug_actiongroup_page.php.
POC
Reference
- http://securityreason.com/securityalert/8392
- http://securityreason.com/securityalert/8392
- http://www.mantisbt.org/bugs/view.php?id=13281
- http://www.mantisbt.org/bugs/view.php?id=13281
Github
No PoCs found on GitHub currently.