Show filters
42 Total Results
Displaying 41-42 of 42
Sort by:
Attacker Value
Unknown

CVE-2007-4543

Disclosure Date: August 27, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in enter_bug.cgi in Bugzilla 2.17.1 through 2.20.4, 2.22.x before 2.22.3, and 3.x before 3.0.1 allows remote attackers to inject arbitrary web script or HTML via the buildid field in the "guided form."
0
Attacker Value
Unknown

CVE-2007-4539

Disclosure Date: August 27, 2007 (last updated October 04, 2023)
The WebService (XML-RPC) interface in Bugzilla 2.23.3 through 3.0.0 does not enforce permissions for the time-tracking fields of bugs, which allows remote attackers to obtain sensitive information via certain XML-RPC requests, as demonstrated by the (1) Deadline and (2) Estimated Time fields.
0