Show filters
44 Total Results
Displaying 41-44 of 44
Sort by:
Attacker Value
Unknown
CVE-2009-0483
Disclosure Date: February 09, 2009 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.22 before 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote attackers to delete keywords and user preferences via a link or IMG tag to (1) editkeywords.cgi or (2) userprefs.cgi.
0
Attacker Value
Unknown
CVE-2008-4437
Disclosure Date: October 03, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in importxml.pl in Bugzilla before 2.22.5, and 3.x before 3.0.5, when --attach_path is enabled, allows remote attackers to read arbitrary files via an XML file with a .. (dot dot) in the data element.
0
Attacker Value
Unknown
CVE-2008-2103
Disclosure Date: May 07, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Bugzilla 2.17.2 and later allows remote attackers to inject arbitrary web script or HTML via the id parameter to the "Format for Printing" view or "Long Format" bug list.
0
Attacker Value
Unknown
CVE-2008-2105
Disclosure Date: May 07, 2008 (last updated October 04, 2023)
email_in.pl in Bugzilla 2.23.4, 3.0.x before 3.0.4, and 3.1.x before 3.1.4 allows remote authenticated users to more easily spoof the changer of a bug via a @reporter command in the body of an e-mail message, which overrides the e-mail address as normally obtained from the From e-mail header. NOTE: since From headers are easily spoofed, this only crosses privilege boundaries in environments that provide additional verification of e-mail addresses.
0