Summary
The remote web server contains a PHP application that is affected by multiple flaws.
Description :
The remote version of Mantis suffers from a remote file inclusion vulnerability. Provided PHP's 'register_globals' setting is enabled, An attacker may be able to leverage this issue to read arbitrary files on the local host or to execute arbitrary PHP code, possibly taken from third-party hosts.
In addition, the installed version reportedly may be prone to SQL injection, cross-site scripting, and information disclosure attacks.
Solution
Upgrade to Mantis 0.19.3 or newer.
References
Severity
Classification
-
CVE CVE-2005-3335 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities