Mantis suffers from a remote PHP code execution vulnerability when the REGISTER_GLOBAL variable is set.