CVE-2008-3333
Published Jul 27, 2008
Last updated 7 years ago
Overview
- Description
- Directory traversal vulnerability in core/lang_api.php in Mantis before 1.1.2 allows remote attackers to include and execute arbitrary files via the language parameter to the user preferences page (account_prefs_update.php).
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-22
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:mantis:mantis:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D4A66D23-7343-44B3-A8A8-FD39D88AFCC4", "versionEndIncluding": "1.1.1" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0266C2F7-FB20-44EF-B0BB-ECCF055D03A8" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.9.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B5E88349-E374-4AE9-9C4E-9599C1448D21" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.9.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A21FF02F-982C-429F-A14D-D6E18058DD61" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9407F704-FF3C-4976-BE4C-A1DDC16715D0" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.10.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "99FB3D29-644D-4E5F-875D-C87CCE3EF95C" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.10.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A5173B32-1099-47C9-996B-56DB29456BB9" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.10.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A6CA26FD-9C45-4628-82B7-E37E3EA3E2A2" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7B9B4611-C002-40F5-978C-BB90F1A893C3" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.11.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B419B788-ADDD-4C0A-8E02-CBB58FD21938" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.11.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4C7C8B5A-A630-4EDD-A6E8-27D2E1139CF3" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.12:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B347D6C8-4607-481D-863E-7F41E9868041" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.12.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6E387645-BC7A-4EA5-AE9E-A3C66994391B" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.13:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4F434D16-4F09-4BCF-BD3E-9114876C2575" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.13.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C80575A3-87E7-40BC-9BCB-E12BB7938A77" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.13.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F6D8FD23-C9A3-40AB-B3ED-86739BA8A362" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.14:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "72BD480B-7CFB-4FD3-8E47-028F32AEF902" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.14.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "04989B5F-30B2-43A0-A061-BF43EEA8756C" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.14.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AC7C781D-F5D1-4C63-B6E3-230DEC80104E" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.14.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D0755FA0-2365-42B4-8E42-214D5BAD71A1" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.14.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "35248DDA-D37D-4D72-9FF8-6813BA4C87BE" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.14.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A67C54F4-4155-43DA-8E07-579249759989" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.14.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9DE7BEF1-1522-4666-B6B1-36A308FBC0A3" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.14.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C376D216-914A-4D96-8603-C6861B3E2857" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.14.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CF0636CA-49A5-4463-B22B-6C5E1E2D44AC" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.14.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E3A07B4C-CE12-4381-BFE4-CE79411F5069" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.15:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DB6E1BE3-BF57-4ED4-918D-8B23CB195ECE" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.15.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "065C222C-638F-4303-BE6A-7FED59E21FB9" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.15.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BB502B29-FBC5-4984-A735-AA0B6DF4A58D" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.15.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3F759138-7079-471F-B30D-ED62351CFCB9" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.15.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5DF83421-973D-4AC9-BDA3-4161B9CF2D91" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.15.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1633BF3C-89C2-4BEF-9F56-6F19984D3CA3" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.15.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "084BD5F4-37F8-4913-8045-769FD81F8C36" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.15.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "76B09948-A44C-47D8-A5EC-3873FF36F451" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.15.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "89D72C1E-73E5-4F51-9D30-D28026939C57" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.15.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E9EDAA7A-DF0C-4D9E-9D30-0422E4801612" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.15.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2C469C66-B64B-49BD-9D1C-D15F0E9028EF" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.15.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C28223A1-359F-434C-BAAA-82A5F310FA44" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.15.11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7BF1F18B-AE36-48F3-B784-5C97B3F2535E" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.15.12:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F073B8A1-3339-4BF2-B8D1-F6BA5CF9695A" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.16:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3A62328B-4C77-4FF4-B1D9-BE4A2E5C61FF" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.16.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6DAFD163-7FE7-48FB-8860-7B00B0FFA628" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.16.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "03A0C36A-83DF-4E67-BA82-0ACE4D50C7D7" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.17:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7C074DBE-AFC9-4094-A170-A31D79C139D8" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.17.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "53520AA0-E5AB-450A-9D95-E075B552D2E9" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.17.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8462CB86-30B1-43D8-B306-271709423DB2" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.17.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "131A96BB-EF2E-4AE2-9334-91CA96222BA2" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.17.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "17DC6205-7016-40C3-921A-B5AEC8513CCC" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.17.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "721A536A-9626-4BD7-B84A-E3C4074F1217" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.17.4a:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4D77F95A-0059-4442-8D9D-AA7F101FBBE5" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.17.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "89786096-AE1B-491B-8284-DBCC2F6112F0" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.18:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E0BC255D-6B0F-412D-B639-B9F9656E4839" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.18.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "70450FAB-7886-418E-B471-8F16A68F9658" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.18.0_rc1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4B4CFE80-223F-45DA-A9FB-03474F61E027" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.18.0a1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B29FF305-E773-497E-9C47-7D87383F1440" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.18.0a2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8724300D-CBDC-4C66-BF78-038F838C06DF" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.18.0a3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B7283A58-EE8E-493F-8E51-C97FF87ECA16" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.18.0a4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E3CF3162-EAF8-438C-891A-FD13ECF6D6A6" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.18.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1E42F3A0-5FDB-4053-9EA5-D19B7061CDE8" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.18.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "101BF6DC-0F73-41E0-A0EE-BA1EA7397423" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.18.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FCC458D9-12B1-4CF1-980E-BC86E874BBA2" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.18a1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2202C65A-33FB-4742-8706-2BDD5B442030" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.19:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9C6C0D59-A086-4A38-8F94-C35B8A1A0D1B" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.19.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5419E3AC-4215-4584-9538-AF790DC9BD5F" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.19.0_rc1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D3C48B8F-633E-4D69-A174-26C19829DE98" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.19.0a:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C1E7658F-A543-46F5-B79D-E0E25B7C574F" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.19.0a1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DD259C18-7111-45C9-B6C3-6A5F29998146" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.19.0a2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7CBA3B4B-D7E6-4555-969F-66217ACDACDA" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.19.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "38BFDCFA-00C8-4B6A-B758-8FD15A122CA2" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.19.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6770FDC6-792D-49B2-942B-282F9012D0BE" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.19.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8D8E7458-6655-4C86-85A9-81004FF38321" }, { "criteria": "cpe:2.3:a:mantis:mantis:0.19.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AE92E018-C25C-468D-9EF5-5665F0B42EA2" }, { "criteria": "cpe:2.3:a:mantis:mantis:1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2C62F6BC-4397-44BD-A7DA-CD4C52425BE4" }, { "criteria": "cpe:2.3:a:mantis:mantis:1.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "781910F1-C34C-49D6-80D2-62AC80AF17DE" }, { "criteria": "cpe:2.3:a:mantis:mantis:1.0.0_rc1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C6DB707C-29DF-442C-BBBE-650182692A33" }, { "criteria": "cpe:2.3:a:mantis:mantis:1.0.0_rc2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0C420189-4748-465C-96FE-DC89502F7E26" }, { "criteria": "cpe:2.3:a:mantis:mantis:1.0.0_rc3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3B3A1BAC-F777-413E-BFB7-972C687C2D92" }, { "criteria": "cpe:2.3:a:mantis:mantis:1.0.0_rc4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B0C7EDA7-1BED-4152-BD3D-3A596482D9D6" }, { "criteria": "cpe:2.3:a:mantis:mantis:1.0.0_rc5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B54BEEA5-B671-4BDE-96D1-B235CF8F197E" }, { "criteria": "cpe:2.3:a:mantis:mantis:1.0.0a1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "730BE023-C283-4775-915C-79817723917A" }, { "criteria": "cpe:2.3:a:mantis:mantis:1.0.0a2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "337E18A7-07A3-456D-868A-2002F96D7A2A" }, { "criteria": "cpe:2.3:a:mantis:mantis:1.0.0a3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "84B09B6D-EE4D-4241-B3EF-CBCB03A7F579" }, { "criteria": "cpe:2.3:a:mantis:mantis:1.0.0rc1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8B20CB57-A2C4-4491-9A4A-352C699FEF52" }, { "criteria": "cpe:2.3:a:mantis:mantis:1.0.0rc2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DD8DC938-873D-4268-89D1-F16C5796A5C7" }, { "criteria": "cpe:2.3:a:mantis:mantis:1.0.0rc3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B4ED69D6-25B5-4199-B950-165A5FCFEBD9" }, { "criteria": "cpe:2.3:a:mantis:mantis:1.0.0rc4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CF9E3400-610A-4389-B903-9C6CA3D7B9FC" }, { "criteria": "cpe:2.3:a:mantis:mantis:1.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DA5AE0B4-15AB-49E7-9B97-96BA322B0966" }, { "criteria": "cpe:2.3:a:mantis:mantis:1.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "48069606-59B6-4D20-B909-997CA7EDBD2B" }, { "criteria": "cpe:2.3:a:mantis:mantis:1.0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E42CD1CB-49E7-484B-9629-78A24B754346" }, { "criteria": "cpe:2.3:a:mantis:mantis:1.0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F95B327F-94A8-4D4F-A330-1B9BF4B764FD" }, { "criteria": "cpe:2.3:a:mantis:mantis:1.0.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "215420D5-4690-45BE-AE84-CF1522523299" }, { "criteria": "cpe:2.3:a:mantis:mantis:1.0.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5621726F-CA50-4336-9BCE-55F39BE5CDCF" }, { "criteria": "cpe:2.3:a:mantis:mantis:1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C2B0DF8C-FF2D-4DE8-B0D1-92623974A874" }, { "criteria": "cpe:2.3:a:mantis:mantis:1.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "03F4013F-427E-41EE-969C-169B97A14A90" }, { "criteria": "cpe:2.3:a:mantis:mantis:1.1.0a1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F9555553-AEA7-42B3-BE94-7C4729259378" } ], "operator": "OR" } ] } ]