CyberSec.Space Logo
Back to CVE Browser

CVE-2008-4687

CRITICAL
9.0
CVSS Severity Score
EPSS Score0.0690%
EPSS Percentile27.07th
PublishedOct 22, 2008
Last ModifiedApr 23, 2026

Vulnerability Description

manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort parameter containing PHP sequences, which are processed by create_function within the multi_sort function in core/utility_api.php.

Affected Platforms (CPE)

πŸ“¦
Mantis

Mantis

<= 1.1.3
πŸ“¦
Mantis

Mantis

= 0.19.3
πŸ“¦
Mantis

Mantis

= 0.19.4
πŸ“¦
Mantis

Mantis

= 1.0.1
πŸ“¦
Mantis

Mantis

= 1.0.2
πŸ“¦
Mantis

Mantis

= 1.0.3
πŸ“¦
Mantis

Mantis

= 1.0.4
πŸ“¦
Mantis

Mantis

= 1.0.5
πŸ“¦
Mantis

Mantis

= 1.0.6
πŸ“¦
Mantis

Mantis

= 1.0.7
πŸ“¦
Mantis

Mantis

= 1.0.8
πŸ“¦
Mantis

Mantis

= 1.1.1
πŸ“¦
Mantis

Mantis

= 1.1.2

References & Advisories

Related Vulnerabilities