CVE-2018-6382
Dashboard / Vulnerabilities / CVE-2018-6382
CVE-2018-6382
Published: 30 Jan 2018Last Modified: 7 Aug 2026
Summary:
Details: MantisBT 2.10.0 allows local users to conduct SQL Injection attacks via the vendor/adodb/adodb-php/server.php sql parameter in a request to the 127.0.0.1 IP address. NOTE: the vendor disputes the significance of this report because server.php is intended to execute arbitrary SQL statements on behalf of authenticated users from 127.0.0.1, and the issue does not have an authentication bypass
References: http://archive.is/https:/mantisbt.org/bugs/view.php?id=23908, https://mantisbt.org/bugs/view.php?id=23908
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- 9717433ba87f758c57a53e22f533f6d252adb624
Fixed -None
Affected versions
2.10.0
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
