5

CVE-2014-1572

The confirm_create_account function in the account-creation feature in token.cgi in Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 does not specify a scalar context for the realname parameter, which allows remote attackers to create accounts with unverified e-mail addresses by sending three realname values with realname=login_name as the second, as demonstrated by selecting an e-mail address with a domain name for which group privileges are automatically granted.

Data is provided by the National Vulnerability Database (NVD)
FedoraprojectFedora Version19
FedoraprojectFedora Version20
FedoraprojectFedora Version21
MozillaBugzilla Version2.0
MozillaBugzilla Version2.2
MozillaBugzilla Version2.4
MozillaBugzilla Version2.6
MozillaBugzilla Version2.8
MozillaBugzilla Version2.9
MozillaBugzilla Version2.10
MozillaBugzilla Version2.12
MozillaBugzilla Version2.14
MozillaBugzilla Version2.14.1
MozillaBugzilla Version2.14.2
MozillaBugzilla Version2.14.3
MozillaBugzilla Version2.14.4
MozillaBugzilla Version2.14.5
MozillaBugzilla Version2.16
MozillaBugzilla Version2.16 Updaterc1
MozillaBugzilla Version2.16 Updaterc2
MozillaBugzilla Version2.16.1
MozillaBugzilla Version2.16.2
MozillaBugzilla Version2.16.3
MozillaBugzilla Version2.16.4
MozillaBugzilla Version2.16.5
MozillaBugzilla Version2.16.6
MozillaBugzilla Version2.16.7
MozillaBugzilla Version2.16.8
MozillaBugzilla Version2.16.9
MozillaBugzilla Version2.16.10
MozillaBugzilla Version2.16.11
MozillaBugzilla Version2.16_rc2
MozillaBugzilla Version2.17
MozillaBugzilla Version2.17.1
MozillaBugzilla Version2.17.2
MozillaBugzilla Version2.17.3
MozillaBugzilla Version2.17.4
MozillaBugzilla Version2.17.5
MozillaBugzilla Version2.17.6
MozillaBugzilla Version2.17.7
MozillaBugzilla Version2.18
MozillaBugzilla Version2.18 Updaterc1
MozillaBugzilla Version2.18 Updaterc2
MozillaBugzilla Version2.18 Updaterc3
MozillaBugzilla Version2.18.1
MozillaBugzilla Version2.18.2
MozillaBugzilla Version2.18.3
MozillaBugzilla Version2.18.4
MozillaBugzilla Version2.18.5
MozillaBugzilla Version2.18.6
MozillaBugzilla Version2.18.7
MozillaBugzilla Version2.18.8
MozillaBugzilla Version2.18.9
MozillaBugzilla Version2.19
MozillaBugzilla Version2.19.1
MozillaBugzilla Version2.19.2
MozillaBugzilla Version2.19.3
MozillaBugzilla Version2.20
MozillaBugzilla Version2.20 Updaterc1
MozillaBugzilla Version2.20 Updaterc2
MozillaBugzilla Version2.20.1
MozillaBugzilla Version2.20.2
MozillaBugzilla Version2.20.3
MozillaBugzilla Version2.20.4
MozillaBugzilla Version2.20.5
MozillaBugzilla Version2.20.6
MozillaBugzilla Version2.20.7
MozillaBugzilla Version2.21
MozillaBugzilla Version2.21.1
MozillaBugzilla Version2.21.2
MozillaBugzilla Version2.21.2 Updaterc1
MozillaBugzilla Version2.22
MozillaBugzilla Version2.22 Updaterc1
MozillaBugzilla Version2.22.1
MozillaBugzilla Version2.22.2
MozillaBugzilla Version2.22.3
MozillaBugzilla Version2.22.4
MozillaBugzilla Version2.22.5
MozillaBugzilla Version2.22.6
MozillaBugzilla Version2.22.7
MozillaBugzilla Version2.23
MozillaBugzilla Version2.23.1
MozillaBugzilla Version2.23.2
MozillaBugzilla Version2.23.3
MozillaBugzilla Version2.23.4
MozillaBugzilla Version3.0
MozillaBugzilla Version3.0 Updaterc1
MozillaBugzilla Version3.0.0
MozillaBugzilla Version3.0.1
MozillaBugzilla Version3.0.2
MozillaBugzilla Version3.0.3
MozillaBugzilla Version3.0.4
MozillaBugzilla Version3.0.5
MozillaBugzilla Version3.0.6
MozillaBugzilla Version3.0.7
MozillaBugzilla Version3.0.8
MozillaBugzilla Version3.0.9
MozillaBugzilla Version3.0.10
MozillaBugzilla Version3.0.11
MozillaBugzilla Version3.0_rc1
MozillaBugzilla Version3.1.0
MozillaBugzilla Version3.1.1
MozillaBugzilla Version3.1.2
MozillaBugzilla Version3.1.3
MozillaBugzilla Version3.1.4
MozillaBugzilla Version3.2
MozillaBugzilla Version3.2 Updaterc1
MozillaBugzilla Version3.2 Updaterc2
MozillaBugzilla Version3.2.1
MozillaBugzilla Version3.2.2
MozillaBugzilla Version3.2.3
MozillaBugzilla Version3.2.4
MozillaBugzilla Version3.2.5
MozillaBugzilla Version3.2.6
MozillaBugzilla Version3.2.7
MozillaBugzilla Version3.2.8
MozillaBugzilla Version3.2.9
MozillaBugzilla Version3.2.10
MozillaBugzilla Version3.3
MozillaBugzilla Version3.3.1
MozillaBugzilla Version3.3.2
MozillaBugzilla Version3.3.3
MozillaBugzilla Version3.3.4
MozillaBugzilla Version3.4
MozillaBugzilla Version3.4 Updaterc1
MozillaBugzilla Version3.4.1
MozillaBugzilla Version3.4.2
MozillaBugzilla Version3.4.3
MozillaBugzilla Version3.4.4
MozillaBugzilla Version3.4.5
MozillaBugzilla Version3.4.6
MozillaBugzilla Version3.4.7
MozillaBugzilla Version3.4.8
MozillaBugzilla Version3.4.9
MozillaBugzilla Version3.4.10
MozillaBugzilla Version3.4.11
MozillaBugzilla Version3.4.12
MozillaBugzilla Version3.4.13
MozillaBugzilla Version3.5
MozillaBugzilla Version3.5.1
MozillaBugzilla Version3.5.2
MozillaBugzilla Version3.5.3
MozillaBugzilla Version3.6
MozillaBugzilla Version3.6 Updaterc1
MozillaBugzilla Version3.6.0
MozillaBugzilla Version3.6.1
MozillaBugzilla Version3.6.2
MozillaBugzilla Version3.6.3
MozillaBugzilla Version3.6.4
MozillaBugzilla Version3.6.5
MozillaBugzilla Version3.6.6
MozillaBugzilla Version3.6.7
MozillaBugzilla Version3.6.8
MozillaBugzilla Version3.6.9
MozillaBugzilla Version3.6.10
MozillaBugzilla Version3.6.11
MozillaBugzilla Version3.6.12
MozillaBugzilla Version3.6.13
MozillaBugzilla Version3.7
MozillaBugzilla Version3.7.1
MozillaBugzilla Version3.7.2
MozillaBugzilla Version3.7.3
MozillaBugzilla Version4.0
MozillaBugzilla Version4.0 Updaterc1
MozillaBugzilla Version4.0 Updaterc2
MozillaBugzilla Version4.0.1
MozillaBugzilla Version4.0.10
MozillaBugzilla Version4.0.11
MozillaBugzilla Version4.0.12
MozillaBugzilla Version4.0.13
MozillaBugzilla Version4.0.14
MozillaBugzilla Version4.1
MozillaBugzilla Version4.1.1
MozillaBugzilla Version4.1.2
MozillaBugzilla Version4.1.3
MozillaBugzilla Version4.2
MozillaBugzilla Version4.2 Updaterc1
MozillaBugzilla Version4.2 Updaterc2
MozillaBugzilla Version4.2.1
MozillaBugzilla Version4.2.2
MozillaBugzilla Version4.2.3
MozillaBugzilla Version4.2.4
MozillaBugzilla Version4.2.5
MozillaBugzilla Version4.2.6
MozillaBugzilla Version4.2.7
MozillaBugzilla Version4.2.8
MozillaBugzilla Version4.2.9
MozillaBugzilla Version4.2.10
MozillaBugzilla Version4.3
MozillaBugzilla Version4.3.1
MozillaBugzilla Version4.3.2
MozillaBugzilla Version4.3.3
MozillaBugzilla Version4.4
MozillaBugzilla Version4.4 Updaterc1
MozillaBugzilla Version4.4 Updaterc2
MozillaBugzilla Version4.4.1
MozillaBugzilla Version4.4.2
MozillaBugzilla Version4.4.3
MozillaBugzilla Version4.4.4
MozillaBugzilla Version4.4.5
MozillaBugzilla Version4.5
MozillaBugzilla Version4.5.1
MozillaBugzilla Version4.5.2
MozillaBugzilla Version4.5.3
MozillaBugzilla Version4.5.4
MozillaBugzilla Version4.5.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.1% 0.774
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N