CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2008-4687

CRITICAL
9.0
CVSS Severity Score
EPSS Score0.0690%
EPSS Percentile27.07th
Published2008年10月22日
Last Modified2026年4月23日

Vulnerability Description

manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort parameter containing PHP sequences, which are processed by create_function within the multi_sort function in core/utility_api.php.

Affected Platforms (CPE)

📦
Mantis

Mantis

<= 1.1.3
📦
Mantis

Mantis

= 0.19.3
📦
Mantis

Mantis

= 0.19.4
📦
Mantis

Mantis

= 1.0.1
📦
Mantis

Mantis

= 1.0.2
📦
Mantis

Mantis

= 1.0.3
📦
Mantis

Mantis

= 1.0.4
📦
Mantis

Mantis

= 1.0.5
📦
Mantis

Mantis

= 1.0.6
📦
Mantis

Mantis

= 1.0.7
📦
Mantis

Mantis

= 1.0.8
📦
Mantis

Mantis

= 1.1.1
📦
Mantis

Mantis

= 1.1.2

References & Advisories

相關漏洞威脅