Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
If, after successful installation of MantisBT through 2.5.2 on MySQL/MariaDB, the administrator does not remove the 'admin' directory (as recommended in the "Post-installation and upgrade tasks" section of the MantisBT Admin Guide), and the MySQL client has a local_infile setting enabled (in php.ini mysqli.allow_local_infile, or the MySQL client config file, depending on the PHP setup), an attacker may take advantage of MySQL's "connect file read" feature to remotely access files on the MantisBT server.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
MySQL/MariaDB MantisBT 安全漏洞
Vulnerability Description
Oracle MySQL是美国甲骨文(Oracle)公司的一套开源的关系数据库管理系统。该数据库系统具有性能高、成本低、可靠性好等特点。MariaDB是美国Monty Program Ab公司和美国MariaDB基金会共同开发的一套免费开源的数据库管理系统。MantisBT是其中的一个MantisBT团队开发的基于Web的开源缺陷跟踪系统。 MySQL/MariaDB上的MantisBT 2.5.2及之前的版本中存在安全漏洞。远程攻击者可利用该漏洞访问MantisBT服务器上的文件。
CVSS Information
N/A
Vulnerability Type
N/A