Information disclosure in MantisBT - CVE-2014-9279
Published: December 8, 2014 / Updated: August 9, 2020
MantisBT
mantisbt.sourceforge.net
Description
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
The print_test_result function in admin/upgrade_unattended.php in MantisBT 1.1.0a3 through 1.2.x before 1.2.18 allows remote attackers to obtain database credentials via a URL in the hostname parameter and reading the parameters in the response sent to the URL.