20040820 Multiple Vulnerabilities in Mantis Bugtrackermailing list
http://marc.info/?l=bugtraq&m=109312225727345&w=2 CVE-2004-1731
Mantis Bug Tracker 0.x - New Account Signup Mass Emailing
Record summary
CVE-2004-1731 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
signup_page.php in Mantis bugtracker allows remote attackers to send e-mail bombs by creating multiple users and providing the same e-mail address.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBMantis Bug Tracker 0.x - New Account Signup Mass EmailingExploitDB exploitby Jose AntonioNot analyzed1 file
References
410995vdb entry
http://www.securityfocus.com/bid/10995 mantis-improper-account-validation(17093)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/17093 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-1731