CVE

Id
34805  
CVE No.
CVE-2008-4688  
Status
Candidate  
Description
core/string_api.php in Mantis before 1.1.3 does not check the privileges of the viewer before composing a link with issue data in the source anchor, which allows remote attackers to discover an issue"s title and status via a request with a modified issue number.  
Phase
Assigned (20081022)  
Votes
None (candidate not yet proposed)  
Comments