MantisBT: master-1.2.x a608f2d0

Author Committer Branch Timestamp Parent
dregad dregad master-1.2.x 2014-02-28 07:23 master-1.2.x 4009cc03
Affected Issues  0017055: CVE-2014-2238: SQL injection vulnerability in adm_config_report.php
Changeset

Fix SQL injection vulnerability in adm_config_report.php

Jakub Galczyk (HauntIT blog http://hauntit.blogspot.com/) reported this
issue, introduced by f8a81a33880752364ea47bdd9a987bff986c81de in
MantisBT 1.2.13.

Root cause is the use of unsanitized inlined query parameters.

Fixes 0017055

mod - adm_config_report.php Diff File