CVE-2004-1731

Mantis Bugtracker - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2004-1731. PoCs published by Jose Antonio.

AI-analyzed exploit summary This exploit demonstrates a mass email attack vulnerability in Mantis by repeatedly creating new user accounts with the same email address, causing the system to send multiple emails to the target address. The script automates the process by sending HTTP requests to the signup endpoint.

Description

signup_page.php in Mantis bugtracker allows remote attackers to send e-mail bombs by creating multiple users and providing the same e-mail address.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Jose Antonio · phpwebappsphp
https://www.exploit-db.com/exploits/24392

This exploit demonstrates a mass email attack vulnerability in Mantis by repeatedly creating new user accounts with the same email address, causing the system to send multiple emails to the target address. The script automates the process by sending HTTP requests to the signup endpoint.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Mantis (versions prior to CVS with CAPTCHA implementation)
No auth needed
Prerequisites: Access to the Mantis signup endpoint · Valid target email address
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/17093
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/10995
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=109312225727345&w=2

Scores

EPSS 0.0320
EPSS Percentile 86.5%

Details

Status published
Products (50)
mantis/mantis 0.9
mantis/mantis 0.9.1
mantis/mantis 0.10
mantis/mantis 0.10.1
mantis/mantis 0.10.2
mantis/mantis 0.11
mantis/mantis 0.11.1
mantis/mantis 0.12
mantis/mantis 0.13
mantis/mantis 0.13.1
... and 40 more
Published Aug 20, 2004
Tracked Since Feb 18, 2026