- EPSS 0.65%
- Veröffentlicht 03.02.2010 19:30:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
Bugzilla 3.3.1 through 3.4.4, 3.5.1, and 3.5.2 does not allow group restrictions to be preserved throughout the process of moving a bug to a different product category, which allows remote attackers to obtain sensitive information via a request for a...
CVE-2009-3989
- EPSS 0.65%
- Veröffentlicht 03.02.2010 19:30:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests fo...
- EPSS 0.65%
- Veröffentlicht 20.11.2009 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Template.pm in Bugzilla 3.3.2 through 3.4.3 and 3.5 through 3.5.1 allows remote attackers to discover the alias of a private bug by reading the (1) Depends On or (2) Blocks field of a related bug.
CVE-2009-3125
- EPSS 0.33%
- Veröffentlicht 15.09.2009 22:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
SQL injection vulnerability in the Bug.search WebService function in Bugzilla 3.3.2 through 3.4.1, and 3.5, allows remote attackers to execute arbitrary SQL commands via unspecified parameters.
CVE-2009-3165
- EPSS 0.33%
- Veröffentlicht 15.09.2009 22:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
SQL injection vulnerability in the Bug.create WebService function in Bugzilla 2.23.4 through 3.0.8, 3.1.1 through 3.2.4, and 3.3.1 through 3.4.1 allows remote attackers to execute arbitrary SQL commands via unspecified parameters.
- EPSS 0.36%
- Veröffentlicht 15.09.2009 22:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
token.cgi in Bugzilla 3.4rc1 through 3.4.1 places a password in a URL at the beginning of a login session that occurs immediately after a password reset, which allows context-dependent attackers to discover passwords by reading (1) web-server access ...
CVE-2009-1213
- EPSS 0.35%
- Veröffentlicht 01.04.2009 10:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 3.2 before 3.2.3, 3.3 before 3.3.4, and earlier versions allows remote attackers to hijack the authentication of arbitrary users for requests that use attachment editing.
- EPSS 0.38%
- Veröffentlicht 09.02.2009 18:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Bugzilla 3.2 before 3.2 RC2, 3.0 before 3.0.6, 2.22 before 2.22.6, 2.20 before 2.20.7, and other versions after 2.17.4 allows remote authenticated users to bypass moderation to approve and disapprove quips via a direct request to quips.cgi with the a...
CVE-2009-0481
- EPSS 0.23%
- Veröffentlicht 09.02.2009 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Bugzilla 2.x before 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote authenticated users to conduct cross-site scripting (XSS) and related attacks by uploading HTML and JavaScript attachments that are rendered by web bro...
CVE-2009-0482
- EPSS 0.27%
- Veröffentlicht 09.02.2009 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site request forgery (CSRF) vulnerability in Bugzilla before 3.2 before 3.2.1, 3.3 before 3.3.2, and other versions before 3.2 allows remote attackers to perform bug updating activities as other users via a link or IMG tag to process_bug.cgi.