Show filters
71 Total Results
Displaying 31-40 of 71
Sort by:
Attacker Value
Unknown
CVE-2009-0482
Disclosure Date: February 09, 2009 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in Bugzilla before 3.2 before 3.2.1, 3.3 before 3.3.2, and other versions before 3.2 allows remote attackers to perform bug updating activities as other users via a link or IMG tag to process_bug.cgi.
0
Attacker Value
Unknown
CVE-2009-0483
Disclosure Date: February 09, 2009 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.22 before 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote attackers to delete keywords and user preferences via a link or IMG tag to (1) editkeywords.cgi or (2) userprefs.cgi.
0
Attacker Value
Unknown
CVE-2008-2105
Disclosure Date: May 07, 2008 (last updated October 04, 2023)
email_in.pl in Bugzilla 2.23.4, 3.0.x before 3.0.4, and 3.1.x before 3.1.4 allows remote authenticated users to more easily spoof the changer of a bug via a @reporter command in the body of an e-mail message, which overrides the e-mail address as normally obtained from the From e-mail header. NOTE: since From headers are easily spoofed, this only crosses privilege boundaries in environments that provide additional verification of e-mail addresses.
0
Attacker Value
Unknown
CVE-2005-4534
Disclosure Date: December 28, 2005 (last updated February 22, 2025)
The shadow database feature (syncshadowdb) in Bugzilla 2.9 through 2.16.10 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
0
Attacker Value
Unknown
CVE-2005-1563
Disclosure Date: May 14, 2005 (last updated February 22, 2025)
Bugzilla 2.10 through 2.18, 2.19.1, and 2.19.2 displays a different error message depending on whether a product exists or not, which allows remote attackers to determine hidden products.
0
Attacker Value
Unknown
CVE-2005-1565
Disclosure Date: May 12, 2005 (last updated February 22, 2025)
Bugzilla 2.17.1 through 2.18, 2.19.1, and 2.19.2, when a user is prompted to log in while attempting to view a chart, displays the password in the URL, which may allow local users to gain sensitive information from web logs or browser history.
0
Attacker Value
Unknown
CVE-2005-1564
Disclosure Date: May 12, 2005 (last updated February 22, 2025)
post_bug.cgi in Bugzilla 2.10 through 2.18, 2.19.1, and 2.19.2 allows remote authenticated users to "enter bugs into products that are closed for bug entry" by modifying the URL to specify the name of the product.
0
Attacker Value
Unknown
CVE-2004-1633
Disclosure Date: October 25, 2004 (last updated February 22, 2025)
process_bug.cgi in Bugzilla 2.9 through 2.18rc2 and 2.19 from CVS does not check edit permissions on the keywords field, which allows remote authenticated users to modify the keywords in a bug via the keywordaction parameter.
0
Attacker Value
Unknown
CVE-2004-1634
Disclosure Date: October 25, 2004 (last updated February 22, 2025)
show_bug.cgi in Bugzilla 2.17.1 through 2.18rc2 and 2.19 from CVS, when using the insidergroup feature and exporting a bug to XML, shows comments and attachment summaries which are marked as private, which allows remote attackers to gain sensitive information.
0
Attacker Value
Unknown
CVE-2003-1046
Disclosure Date: August 18, 2004 (last updated February 22, 2025)
describecomponents.cgi in Bugzilla 2.17.3 and 2.17.4 does not properly verify group membership when bug entry groups are used, which allows remote attackers to list component descriptions for otherwise restricted products.
0