CVE-2014-2238

Publication date 5 March 2014

Last updated 24 July 2024


Ubuntu priority

Description

SQL injection vulnerability in the manage configuration page (adm_config_report.php) in MantisBT 1.2.13 through 1.2.16 allows remote authenticated administrators to execute arbitrary SQL commands via the filter_config_id parameter.

Status

Package Ubuntu Release Status
mantis 13.10 saucy
Not affected
12.10 quantal
Not affected
12.04 LTS precise
Not affected
10.04 LTS lucid
Not affected


Access our resources on patching vulnerabilities