CVE-2014-1608
published 2014-03-18CVE-2014-1608: SQL injection vulnerability in the mci_file_get function in api/soap/mc_file_api.php in MantisBT before 1.2.16 allows remote attackers to execute arbitrary SQL…
PriorityP348high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.14%
86.4th percentile
SQL injection vulnerability in the mci_file_get function in api/soap/mc_file_api.php in MantisBT before 1.2.16 allows remote attackers to execute arbitrary SQL commands via a crafted envelope tag in a mc_issue_attachment_get SOAP request.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| mantisbt | mantisbt | <= 1.2.15 | — |
| mantisbt | mantisbt | — | — |
| mantisbt | mantisbt | — | — |
| mantisbt | mantisbt | — | — |
| mantisbt | mantisbt | — | — |
| mantisbt | mantisbt | — | — |
| mantisbt | mantisbt | — | — |
| mantisbt | mantisbt | — | — |
| mantisbt | mantisbt | — | — |
| mantisbt | mantisbt | — | — |
| mantisbt | mantisbt | — | — |
| mantisbt | mantisbt | — | — |
| mantisbt | mantisbt | — | — |
| mantisbt | mantisbt | — | — |
| mantisbt | mantisbt | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4pj9-mpj4-ccm8: Multiple SQL injection vulnerabilities in MantisBT before 1
ghsa_unreviewed·2022-05-13·CVSS 7.5
CVE-2014-1609 [HIGH] CWE-89 GHSA-4pj9-mpj4-ccm8: Multiple SQL injection vulnerabilities in MantisBT before 1
Multiple SQL injection vulnerabilities in MantisBT before 1.2.16 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to the (1) mc_project_get_attachments function in api/soap/mc_project_api.php; the (2) news_get_limited_rows function in core/news_api.php; the (3) summary_print_by_enum, (4) summary_print_by_age, (5) summary_print_by_developer, (6) summary_print_by_reporter, or (7) summary_print_by_category function in core/summary_api.php; the (8) create_bug_enum_summary or (9) enum_bug_group function in plugins/MantisGraph/core/graph_api.php; (10) bug_graph_bycategory.php or (11) bug_graph_bystatus.php in plugins/MantisGraph/pages/; or (12) proj_doc_page.php, related to use of the db_query function, a different vulnerability than CVE-2014-1608.
GHSA
GHSA-2qwf-fhm6-c4w3: SQL injection vulnerability in the mci_file_get function in api/soap/mc_file_api
ghsa_unreviewed·2022-05-13
CVE-2014-1608 [HIGH] CWE-89 GHSA-2qwf-fhm6-c4w3: SQL injection vulnerability in the mci_file_get function in api/soap/mc_file_api
SQL injection vulnerability in the mci_file_get function in api/soap/mc_file_api.php in MantisBT before 1.2.16 allows remote attackers to execute arbitrary SQL commands via a crafted envelope tag in a mc_issue_attachment_get SOAP request.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-1608 CVE-2014-1609 mantis: SQL injection issues
bugzilla·2014-02-10·CVSS 7.5
CVE-2014-1608 [HIGH] CVE-2014-1608 CVE-2014-1609 mantis: SQL injection issues
CVE-2014-1608 CVE-2014-1609 mantis: SQL injection issues
SQL injection issues were discovered in MantisBT, an open source issue tracker.
CVE-2014-1608 patch:
https://github.com/mantisbt/mantisbt/commit/00b4c17088fa56594d85fe46b6c6057bb3421102
CVE-2014-1609 patch:
https://github.com/mantisbt/mantisbt/commit/7efe0175f0853e18ebfacedfd2374c4179028b3f
It was reported that versions 1.1.0a4 to 1.2.15 are affected.
References:
http://www.ocert.org/advisories/ocert-2014-001.html
Discussion:
Created mantis tracking bugs for this issue:
Affects: fedora-all [bug 1063113]
Affects: epel-5 [bug 1063114]
---
mantis-1.2.17-1.fc19 has been pushed to the Fedora 19 stable repository. If problems still persist, please make note of it in this bug report.
---
mantis-1.2.17-1.fc20 has been pushed to t
Bugzilla
CVE-2014-1609 CVE-2014-1608 mantis: SQL injection issues [fedora-all]
bugzilla·2014-02-10·CVSS 7.5
CVE-2014-1609 [HIGH] CVE-2014-1609 CVE-2014-1608 mantis: SQL injection issues [fedora-all]
CVE-2014-1609 CVE-2014-1608 mantis: SQL injection issues [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects mul
Bugzilla
CVE-2014-1609 CVE-2014-1608 mantis: SQL injection issues [epel-5]
bugzilla·2014-02-10·CVSS 7.5
CVE-2014-1609 [HIGH] CVE-2014-1609 CVE-2014-1608 mantis: SQL injection issues [epel-5]
CVE-2014-1609 CVE-2014-1608 mantis: SQL injection issues [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-5 tracking bug for mantis: se
arXiv
Fixing Vulnerabilities Potentially Hinders Maintainability
arxiv_fulltext·2021-09-12
Fixing Vulnerabilities Potentially Hinders Maintainability
Fixing Vulnerabilities Potentially Hinders Maintainability
Sofia Reis
Rui Abreu
Luis Cruz
Sofia Reis
INESC ID and IST, University of Lisbon, Lisbon, Portugal
[email protected]
Rui Abreu
INESC ID and FEUP, University of Porto, Porto, Portugal
[email protected]
Luis Cruz
Delft University of Technology, Delft, The Netherlands
[email protected]
Received: date / Accepted: date
## Abstract
Security is a requirement of utmost importance to produce
high-quality software. However, there is still a considerable amount
of vulnerabilities being discovered and fixed almost weekly. We
hypothesize that developers affect the maintainability of their
codebases when patching vulnerabilities. This paper evaluates the
impact of patches to improve security on the maintainability of
open-
http://osvdb.org/103118http://secunia.com/advisories/61432http://www.debian.org/security/2014/dsa-3030http://www.mantisbt.org/bugs/view.php?id=16879http://www.ocert.org/advisories/ocert-2014-001.htmlhttp://www.securityfocus.com/bid/65445https://bugzilla.redhat.com/show_bug.cgi?id=1063111https://github.com/mantisbt/mantisbt/commit/00b4c17088fa56594d85fe46b6c6057bb3421102http://osvdb.org/103118http://secunia.com/advisories/61432http://www.debian.org/security/2014/dsa-3030http://www.mantisbt.org/bugs/view.php?id=16879http://www.ocert.org/advisories/ocert-2014-001.htmlhttp://www.securityfocus.com/bid/65445https://bugzilla.redhat.com/show_bug.cgi?id=1063111https://github.com/mantisbt/mantisbt/commit/00b4c17088fa56594d85fe46b6c6057bb3421102
2014-03-18
Published