Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
view_all_bug_page.php in MantisBT 2.10.0-development before 2018-02-02 allows remote attackers to discover the full path via an invalid filter parameter, related to a filter_ensure_valid_filter call in current_user_api.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
MantisBT 安全漏洞
Vulnerability Description
MantisBT是MantisBT团队的一套基于Web的开源缺陷跟踪系统。该系统以Web操作的形式提供项目管理及缺陷跟踪服务。 MantisBT 2018-02-02之前版本中的view_all_bug_page.php文件存在安全漏洞。远程攻击者可借助无效的‘filter’参数利用该漏洞获取完整路径。
CVSS Information
N/A
Vulnerability Type
N/A