Vulnerability Description
Mantis before 1.1.0a2 sets the default value of $g_bug_reminder_threshold to "reporter" instead of a more privileged role, which has unknown impact and attack vectors, possibly related to frequency of reminders.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mantis | Mantis | <= 1.1.0a1 |
References
- http://sourceforge.net/project/shownotes.php?release_id=469627Patch
- http://www.mantisbugtracker.com/changelog.php
- http://sourceforge.net/project/shownotes.php?release_id=469627Patch
- http://www.mantisbugtracker.com/changelog.php
FAQ
What is CVE-2006-6515?
CVE-2006-6515 is a vulnerability with a CVSS score of 10.0 (HIGH). Mantis before 1.1.0a2 sets the default value of $g_bug_reminder_threshold to "reporter" instead of a more privileged role, which has unknown impact and attack vectors, possibly related to frequency of...
How severe is CVE-2006-6515?
CVE-2006-6515 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-6515?
Check the references section above for vendor advisories and patch information. Affected products include: Mantis Mantis.