3.5

CVE-2008-2105

email_in.pl in Bugzilla 2.23.4, 3.0.x before 3.0.4, and 3.1.x before 3.1.4 allows remote authenticated users to more easily spoof the changer of a bug via a @reporter command in the body of an e-mail message, which overrides the e-mail address as normally obtained from the From e-mail header.  NOTE: since From headers are easily spoofed, this only crosses privilege boundaries in environments that provide additional verification of e-mail addresses.

Data is provided by the National Vulnerability Database (NVD)
MozillaBugzilla Version2.4
MozillaBugzilla Version2.6
MozillaBugzilla Version2.8
MozillaBugzilla Version2.10
MozillaBugzilla Version2.12
MozillaBugzilla Version2.14
MozillaBugzilla Version2.14.1
MozillaBugzilla Version2.14.2
MozillaBugzilla Version2.14.3
MozillaBugzilla Version2.14.4
MozillaBugzilla Version2.14.5
MozillaBugzilla Version2.16 Updaterc1
MozillaBugzilla Version2.16.1
MozillaBugzilla Version2.16.2
MozillaBugzilla Version2.16.3
MozillaBugzilla Version2.16.4
MozillaBugzilla Version2.16.5
MozillaBugzilla Version2.16.6
MozillaBugzilla Version2.16.7
MozillaBugzilla Version2.16.8
MozillaBugzilla Version2.16.9
MozillaBugzilla Version2.16.10
MozillaBugzilla Version2.16.11
MozillaBugzilla Version2.16_rc2
MozillaBugzilla Version2.17.1
MozillaBugzilla Version2.17.2
MozillaBugzilla Version2.17.3
MozillaBugzilla Version2.17.4
MozillaBugzilla Version2.17.5
MozillaBugzilla Version2.17.6
MozillaBugzilla Version2.17.7
MozillaBugzilla Version2.18 Updaterc1
MozillaBugzilla Version2.18 Updaterc2
MozillaBugzilla Version2.18 Updaterc3
MozillaBugzilla Version2.18.1
MozillaBugzilla Version2.18.2
MozillaBugzilla Version2.18.3
MozillaBugzilla Version2.18.4
MozillaBugzilla Version2.18.5
MozillaBugzilla Version2.18.6
MozillaBugzilla Version2.19.1
MozillaBugzilla Version2.19.2
MozillaBugzilla Version2.19.3
MozillaBugzilla Version2.20 Updaterc1
MozillaBugzilla Version2.20 Updaterc2
MozillaBugzilla Version2.20.1
MozillaBugzilla Version2.20.2
MozillaBugzilla Version2.20.3
MozillaBugzilla Version2.20.4
MozillaBugzilla Version2.20.5
MozillaBugzilla Version2.20.6
MozillaBugzilla Version2.21.1
MozillaBugzilla Version2.21.2
MozillaBugzilla Version2.22
MozillaBugzilla Version2.22 Updaterc1
MozillaBugzilla Version2.22.1
MozillaBugzilla Version2.22.2
MozillaBugzilla Version2.22.3
MozillaBugzilla Version2.22.4
MozillaBugzilla Version2.23
MozillaBugzilla Version2.23.1
MozillaBugzilla Version2.23.2
MozillaBugzilla Version2.23.3
MozillaBugzilla Version2.23.4
MozillaBugzilla Version3.0.0
MozillaBugzilla Version3.0.1
MozillaBugzilla Version3.0.2
MozillaBugzilla Version3.1.0
MozillaBugzilla Version3.1.1
MozillaBugzilla Version3.1.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.5% 0.631
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:N/I:P/A:N