gpc_api.php in MantisBT 1.2.17 and earlier allows remote attackers to bypass authenticated via a password starting will a null byte, which triggers an unauthenticated bind.Referenceshttp://www.openwall.com/lists/oss-security/2014/09/12/14http://www.openwall.com/lists/oss-security/2014/09/12/11http://www.mantisbt.org/bugs/view.php?id=17640http://www.openwall.com/lists/oss-security/2014/09/13/1