← Back

CVE-2008-3333

nvd nist
Published: Jul 27, 2008Modified: Apr 23, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

Directory traversal vulnerability in core/lang_api.php in Mantis before 1.1.2 allows remote attackers to include and execute arbitrary files via the language parameter to the user preferences page (account_prefs_update.php).

Affected (95)

Products: Mantis: Mantis
1 product
Mantis
Configuration A
95 vulnerable
Vulnerable SoftwareAffected Versions
Mantis
Up to 1.1.1
Version 0.10.0
Version 0.10.1
Version 0.10.2
Version 0.10
Version 0.11.0
Version 0.11.1
Version 0.11
Version 0.12.0
Version 0.12
Version 0.13.0
Version 0.13.1
Version 0.13
Version 0.14.0
Version 0.14.1
Version 0.14.2
Version 0.14.3
Version 0.14.4
Version 0.14.5
Version 0.14.6
Version 0.14.7
Version 0.14.8
Version 0.14
Version 0.15.0
Version 0.15.10
Version 0.15.11
Version 0.15.12
Version 0.15.1
Version 0.15.2
Version 0.15.3
Version 0.15.4
Version 0.15.5
Version 0.15.6
Version 0.15.7
Version 0.15.8
Version 0.15.9
Version 0.15
Version 0.16.0
Version 0.16.1
Version 0.16
Version 0.17.0
Version 0.17.1
Version 0.17.2
Version 0.17.3
Version 0.17.4
Version 0.17.4a
Version 0.17.5
Version 0.17
Version 0.18.0
Version 0.18.0_rc1
Version 0.18.0a1
Version 0.18.0a2
Version 0.18.0a3
Version 0.18.0a4
Version 0.18.1
Version 0.18.2
Version 0.18.3
Version 0.18
Version 0.18a1
Version 0.19.0
Version 0.19.0_rc1
Version 0.19.0a1
Version 0.19.0a2
Version 0.19.0a
Version 0.19.1
Version 0.19.2
Version 0.19.3
Version 0.19.4
Version 0.19
Version 0.9.0
Version 0.9.1
Version 0.9
Version 1.0.0
Version 1.0.0_rc1
Version 1.0.0_rc2
Version 1.0.0_rc3
Version 1.0.0_rc4
Version 1.0.0_rc5
Version 1.0.0a1
Version 1.0.0a2
Version 1.0.0a3
Version 1.0.0rc1
Version 1.0.0rc2
Version 1.0.0rc3
Version 1.0.0rc4
Version 1.0.1
Version 1.0.2
Version 1.0.3
Version 1.0.4
Version 1.0.5
Version 1.0.6
Version 1.0
Version 1.1.0
Version 1.1.0a1
Version 1.1

References (18)

Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.