CVE-2008-3332
Eval injection vulnerability in adm_config_set.php in Mantis before 1.1.2 allows remote authenticated administrators to execute arbitrary code via the value parameter.
- Affected products
- Mantis
- Mantis
- ≤ 1.1.1, 0.9, 0.9.0, 0.9.1, 0.10, 0.10.0, 0.10.1, 0.10.2, 0.11, 0.11.0, 0.11.1, 0.12, 0.12.0, 0.13, 0.13.0, 0.13.1, 0.14, 0.14.0, 0.14.1, 0.14.2, 0.14.3, 0.14.4, 0.14.5, 0.14.6, 0.14.7, 0.14.8, 0.15, 0.15.0, 0.15.1, 0.15.2, 0.15.3, 0.15.4, 0.15.5, 0.15.6, 0.15.7, 0.15.8, 0.15.9, 0.15.10, 0.15.11, 0.15.12
- Fix
- Available
- CVSS 2.0
- 6.5 MEDIUM
- EPSS
- 9.5% (95th percentile)
- Weakness
- CWE-94
- NVD status
- Modified
- Published
- 2008-07-27
CVE-2008-3332 at NVD
1 known exploit for CVE-2008-3332
Proof-of-concept code and exploit modules indexed by Sploitus