Show filters
56 Total Results
Displaying 31-40 of 56
Sort by:
Attacker Value
Unknown

CVE-2009-0483

Disclosure Date: February 09, 2009 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.22 before 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote attackers to delete keywords and user preferences via a link or IMG tag to (1) editkeywords.cgi or (2) userprefs.cgi.
0
Attacker Value
Unknown

CVE-2008-2105

Disclosure Date: May 07, 2008 (last updated October 04, 2023)
email_in.pl in Bugzilla 2.23.4, 3.0.x before 3.0.4, and 3.1.x before 3.1.4 allows remote authenticated users to more easily spoof the changer of a bug via a @reporter command in the body of an e-mail message, which overrides the e-mail address as normally obtained from the From e-mail header. NOTE: since From headers are easily spoofed, this only crosses privilege boundaries in environments that provide additional verification of e-mail addresses.
0
Attacker Value
Unknown

CVE-2005-4534

Disclosure Date: December 28, 2005 (last updated February 22, 2025)
The shadow database feature (syncshadowdb) in Bugzilla 2.9 through 2.16.10 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
0
Attacker Value
Unknown

CVE-2005-1563

Disclosure Date: May 14, 2005 (last updated February 22, 2025)
Bugzilla 2.10 through 2.18, 2.19.1, and 2.19.2 displays a different error message depending on whether a product exists or not, which allows remote attackers to determine hidden products.
0
Attacker Value
Unknown

CVE-2005-1565

Disclosure Date: May 12, 2005 (last updated February 22, 2025)
Bugzilla 2.17.1 through 2.18, 2.19.1, and 2.19.2, when a user is prompted to log in while attempting to view a chart, displays the password in the URL, which may allow local users to gain sensitive information from web logs or browser history.
0
Attacker Value
Unknown

CVE-2005-1564

Disclosure Date: May 12, 2005 (last updated February 22, 2025)
post_bug.cgi in Bugzilla 2.10 through 2.18, 2.19.1, and 2.19.2 allows remote authenticated users to "enter bugs into products that are closed for bug entry" by modifying the URL to specify the name of the product.
0
Attacker Value
Unknown

CVE-2004-1633

Disclosure Date: October 25, 2004 (last updated February 22, 2025)
process_bug.cgi in Bugzilla 2.9 through 2.18rc2 and 2.19 from CVS does not check edit permissions on the keywords field, which allows remote authenticated users to modify the keywords in a bug via the keywordaction parameter.
0
Attacker Value
Unknown

CVE-2004-1634

Disclosure Date: October 25, 2004 (last updated February 22, 2025)
show_bug.cgi in Bugzilla 2.17.1 through 2.18rc2 and 2.19 from CVS, when using the insidergroup feature and exporting a bug to XML, shows comments and attachment summaries which are marked as private, which allows remote attackers to gain sensitive information.
0
Attacker Value
Unknown

CVE-2003-1046

Disclosure Date: August 18, 2004 (last updated February 22, 2025)
describecomponents.cgi in Bugzilla 2.17.3 and 2.17.4 does not properly verify group membership when bug entry groups are used, which allows remote attackers to list component descriptions for otherwise restricted products.
0
Attacker Value
Unknown

CVE-2003-1043

Disclosure Date: August 18, 2004 (last updated February 22, 2025)
SQL injection vulnerability in Bugzilla 2.16.3 and earlier, and 2.17.1 through 2.17.4, allows remote authenticated users with editkeywords privileges to execute arbitrary SQL via the id parameter to editkeywords.cgi.
0