Show filters
35 Total Results
Displaying 31-35 of 35
Sort by:
Attacker Value
Unknown

CVE-2009-3387

Disclosure Date: February 03, 2010 (last updated October 04, 2023)
Bugzilla 3.3.1 through 3.4.4, 3.5.1, and 3.5.2 does not allow group restrictions to be preserved throughout the process of moving a bug to a different product category, which allows remote attackers to obtain sensitive information via a request for a bug in opportunistic circumstances.
0
Attacker Value
Unknown

CVE-2009-3386

Disclosure Date: November 20, 2009 (last updated October 04, 2023)
Template.pm in Bugzilla 3.3.2 through 3.4.3 and 3.5 through 3.5.1 allows remote attackers to discover the alias of a private bug by reading the (1) Depends On or (2) Blocks field of a related bug.
0
Attacker Value
Unknown

CVE-2009-3165

Disclosure Date: September 15, 2009 (last updated October 04, 2023)
SQL injection vulnerability in the Bug.create WebService function in Bugzilla 2.23.4 through 3.0.8, 3.1.1 through 3.2.4, and 3.3.1 through 3.4.1 allows remote attackers to execute arbitrary SQL commands via unspecified parameters.
0
Attacker Value
Unknown

CVE-2009-3125

Disclosure Date: September 15, 2009 (last updated October 04, 2023)
SQL injection vulnerability in the Bug.search WebService function in Bugzilla 3.3.2 through 3.4.1, and 3.5, allows remote attackers to execute arbitrary SQL commands via unspecified parameters.
0
Attacker Value
Unknown

CVE-2009-1213

Disclosure Date: April 01, 2009 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 3.2 before 3.2.3, 3.3 before 3.3.4, and earlier versions allows remote attackers to hijack the authentication of arbitrary users for requests that use attachment editing.
0