CVE-2004-1734
PHP remote file inclusion vulnerability in Mantis 0.19.0a allows remote attackers to execute arbitrary PHP code by modifying the (1) t_core_path parameter to bug_api.php or (2) t_core_dir parameter to relationship_api.php to reference a URL on a remote web server that contains the code.
- Affected products
- Mantis
- Mantis
- = 0.19.0a
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 1.7% (75th percentile)
- NVD status
- Modified
- Published
- 2005-02-26
CVE-2004-1734 at NVD
No indexed exploits for CVE-2004-1734 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2004-1734 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.