CVE-2005-4518

Publication date 28 December 2005

Last updated 17 July 2025


Ubuntu priority

Description

Mantis before 0.19.4 allows remote attackers to bypass the file upload size restriction by modifying the max_file_size parameter to (1) bug_file_add.php, (2) bug_report.php, (3) bug_report_advanced_page.php, and (4) proj_doc_add_page.php.

Status

Package Ubuntu Release Status
mantis 7.04 feisty
Fixed 0.19.4-2
6.10 edgy
Fixed 0.19.4-2
6.06 LTS dapper
Fixed 0.19.4-2