SQL Injection Vulnerability in Mantis Bug Tracker Software
CVE-2006-0840

Currently unrated

Key Information:

Vendor

Mantis

Status
Vendor
CVE Published:
22 February 2006

What is CVE-2006-0840?

The Mantis Bug Tracker software prior to version 1.00rc5 is susceptible to SQL injection attacks through improper handling of the sort parameter in the manage_user_page.php file. This vulnerability allows remote attackers to exploit the application by inserting quotes into the query, potentially leading to SQL errors that are displayed to users. As a result, attackers can manipulate database queries, which may compromise sensitive information or affect the availability of the application. It is recommended to upgrade to the latest version of Mantis to mitigate these risks.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.