← Back

CVE-2014-8554

nvd nist
Published: Nov 13, 2014Modified: May 6, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

SQL injection vulnerability in the mc_project_get_attachments function in api/soap/mc_project_api.php in MantisBT before 1.2.18 allows remote attackers to execute arbitrary SQL commands via the project_id parameter. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1609.

Affected (75)

Products: Mantisbt: Mantisbt
1 product
Mantisbt
Configuration A
75 vulnerable
Vulnerable SoftwareAffected Versions
Mantisbt
Up to 1.2.17
Version 0.18.0
Version 0.19.0
Version 0.19.0 a1
Version 0.19.0 a2
Version 0.19.0 rc1
Version 0.19.0a1
Version 0.19.0a2
Version 0.19.1
Version 0.19.2
Version 0.19.3
Version 0.19.4
Version 0.19.5
Version 1.0.0
Version 1.0.0 a1
Version 1.0.0 a2
Version 1.0.0 a3
Version 1.0.0 rc1
Version 1.0.0 rc2
Version 1.0.0 rc3
Version 1.0.0 rc4
Version 1.0.0 rc5
Version 1.0.0a1
Version 1.0.0a2
Version 1.0.0a3
Version 1.0.1
Version 1.0.2
Version 1.0.3
Version 1.0.4
Version 1.0.5
Version 1.0.6
Version 1.0.7
Version 1.0.8
Version 1.0.9
Version 1.1.0
Version 1.1.0 a1
Version 1.1.0 a2
Version 1.1.0 a3
Version 1.1.0 a4
Version 1.1.0 rc1
Version 1.1.0 rc2
Version 1.1.0 rc3
Version 1.1.1
Version 1.1.2
Version 1.1.3
Version 1.1.4
Version 1.1.5
Version 1.1.6
Version 1.1.7
Version 1.1.8
Version 1.1.9
Version 1.2.0
Version 1.2.0 alpha1
Version 1.2.0 alpha2
Version 1.2.0 alpha3
Version 1.2.0 rc1
Version 1.2.0 rc2
Version 1.2.0a1
Version 1.2.0a2
Version 1.2.10
Version 1.2.11
Version 1.2.12
Version 1.2.13
Version 1.2.14
Version 1.2.15
Version 1.2.16
Version 1.2.1
Version 1.2.2
Version 1.2.3
Version 1.2.4
Version 1.2.5
Version 1.2.6
Version 1.2.7
Version 1.2.8
Version 1.2.9

References (16)

Source: cve@mitre.org
Exploit
Source: cve@mitre.org
ExploitVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.