SQL Injection Vulnerability in Mantis Bug Tracker Software
CVE-2006-0840
Currently unrated
What is CVE-2006-0840?
The Mantis Bug Tracker software prior to version 1.00rc5 is susceptible to SQL injection attacks through improper handling of the sort parameter in the manage_user_page.php file. This vulnerability allows remote attackers to exploit the application by inserting quotes into the query, potentially leading to SQL errors that are displayed to users. As a result, attackers can manipulate database queries, which may compromise sensitive information or affect the availability of the application. It is recommended to upgrade to the latest version of Mantis to mitigate these risks.
