CVE-2010-4350
MantisBT < 1.2.4 - Remote Code Execution via db_type Parameter in admin/upgrade_unattended.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-4350. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in MantisBT <=1.2.3 via the 'db_type' parameter in 'upgrade_unattended.php'. The vulnerability arises due to improper input validation, allowing directory traversal and inclusion of arbitrary local files.
Description
Directory traversal vulnerability in admin/upgrade_unattended.php in MantisBT before 1.2.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the db_type parameter, related to an unsafe call by MantisBT to a function in the ADOdb Library for PHP.
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in MantisBT <=1.2.3 via the 'db_type' parameter in 'upgrade_unattended.php'. The vulnerability arises due to improper input validation, allowing directory traversal and inclusion of arbitrary local files.