CVE-2008-3333
Publication date 27 July 2008
Last updated 24 July 2024
Ubuntu priority
Description
Directory traversal vulnerability in core/lang_api.php in Mantis before 1.1.2 allows remote attackers to include and execute arbitrary files via the language parameter to the user preferences page (account_prefs_update.php).