CVE-2014-9089
published 2014-11-28CVE-2014-9089: Multiple SQL injection vulnerabilities in view_all_bug_page.php in MantisBT before 1.2.18 allow remote attackers to execute arbitrary SQL commands via the (1)…
PriorityP345high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.42%
82.5th percentile
Multiple SQL injection vulnerabilities in view_all_bug_page.php in MantisBT before 1.2.18 allow remote attackers to execute arbitrary SQL commands via the (1) sort or (2) dir parameter to view_all_set.php.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| mantisbt | mantisbt | <= 1.2.17 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-9089 mantis: SQL injection in view_all_set.php
bugzilla·2014-11-26·CVSS 7.5
CVE-2014-9089 [HIGH] CVE-2014-9089 mantis: SQL injection in view_all_set.php
CVE-2014-9089 mantis: SQL injection in view_all_set.php
It was reported [1][2] that the 'sort' and 'dir' parameters in view_all_set.php are insufficiently validated before being used in queries by view_all_bug_page.php.
Both parameters are split into chunks on ','. After splitting, only the first two values are validated. By supplying a third value, SQL injection can be performed.
This issue is fixed in the upcoming 1.2.8 release. The patch is available at [2].
[1] https://www.mantisbt.org/bugs/view.php?id=17841
[2] http://seclists.org/oss-sec/2014/q4/795
[3] https://github.com/mantisbt/mantisbt/commit/b0021673
Discussion:
Created mantis tracking bugs for this issue:
Affects: fedora-all [bug 1168163]
Affects: epel-5 [bug 1168164]
---
mantis-1.2.18-1.fc19 has been pushed to the Fed
Bugzilla
CVE-2014-9089 mantis: SQL injection in view_all_set.php [epel-5]
bugzilla·2014-11-26·CVSS 7.5
CVE-2014-9089 [HIGH] CVE-2014-9089 mantis: SQL injection in view_all_set.php [epel-5]
CVE-2014-9089 mantis: SQL injection in view_all_set.php [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-5 tracking bug for mantis: see blocks bug list for full det
Bugzilla
CVE-2014-9089 mantis: SQL injection in view_all_set.php [fedora-all]
bugzilla·2014-11-26·CVSS 7.5
CVE-2014-9089 [HIGH] CVE-2014-9089 mantis: SQL injection in view_all_set.php [fedora-all]
CVE-2014-9089 mantis: SQL injection in view_all_set.php [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. W
http://secunia.com/advisories/62101http://www.debian.org/security/2015/dsa-3120http://www.openwall.com/lists/oss-security/2014/11/25/14http://www.openwall.com/lists/oss-security/2014/11/26/6http://www.securityfocus.com/bid/71298https://github.com/mantisbt/mantisbt/commit/b0021673ab23249244119bde3c7fcecd4daa4e7fhttps://www.mantisbt.org/bugs/view.php?id=17841http://secunia.com/advisories/62101http://www.debian.org/security/2015/dsa-3120http://www.openwall.com/lists/oss-security/2014/11/25/14http://www.openwall.com/lists/oss-security/2014/11/26/6http://www.securityfocus.com/bid/71298https://github.com/mantisbt/mantisbt/commit/b0021673ab23249244119bde3c7fcecd4daa4e7fhttps://www.mantisbt.org/bugs/view.php?id=17841
2014-11-28
Published