CVE-2002-1113
summary_graph_functions.php in Mantis 0.17.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the g_jpgraph_path parameter to reference the location of the PHP code.
- Affected products
- Mantis
- Mantis
- = 0.15.3, 0.15.4, 0.15.5, 0.15.6, 0.15.7, 0.15.8, 0.15.9, 0.15.10, 0.15.11, 0.15.12, 0.16.0, 0.16.1, 0.17.0, 0.17.1, 0.17.2, 0.17.3
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 3.3% (88th percentile)
- NVD status
- Modified
- Published
- 2004-09-01
CVE-2002-1113 at NVD
1 known exploit for CVE-2002-1113
Proof-of-concept code and exploit modules indexed by Sploitus