SQL injection in MantisBT and Debian Linux - CVE-2014-1608
Published: March 18, 2014 / Updated: August 10, 2020
Debian
MantisBT
Debian Linux
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary SQL queries in database.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker can send a specially crafted request to the affected application and execute arbitrary SQL commands within the application database.
Successful exploitation of this vulnerability may allow a remote attacker to read, delete, modify data in database and gain complete control over the affected application.
How to mitigate CVE-2014-1608
Sources
- http://osvdb.org/103118
- http://secunia.com/advisories/61432
- http://www.debian.org/security/2014/dsa-3030
- http://www.mantisbt.org/bugs/view.php?id=16879
- http://www.ocert.org/advisories/ocert-2014-001.html
- http://www.securityfocus.com/bid/65445
- https://bugzilla.redhat.com/show_bug.cgi?id=1063111
- https://github.com/mantisbt/mantisbt/commit/00b4c17088fa56594d85fe46b6c6057bb3421102