- EPSS 0.55%
- Published 27.08.2007 21:17:00
- Last modified 09.04.2025 00:30:58
The WebService (XML-RPC) interface in Bugzilla 2.23.3 through 3.0.0 does not enforce permissions for the time-tracking fields of bugs, which allows remote attackers to obtain sensitive information via certain XML-RPC requests, as demonstrated by the ...
CVE-2007-4543
- EPSS 0.72%
- Published 27.08.2007 21:17:00
- Last modified 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in enter_bug.cgi in Bugzilla 2.17.1 through 2.20.4, 2.22.x before 2.22.3, and 3.x before 3.0.1 allows remote attackers to inject arbitrary web script or HTML via the buildid field in the "guided form."
CVE-2007-0791
- EPSS 0.79%
- Published 06.02.2007 19:28:00
- Last modified 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in Atom feeds in Bugzilla 2.20.3, 2.22.1, and 2.23.3, and earlier versions down to 2.20.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2007-0792
- EPSS 0.93%
- Published 06.02.2007 19:28:00
- Last modified 09.04.2025 00:30:58
The mod_perl initialization script in Bugzilla 2.23.3 does not set the Bugzilla Apache configuration to allow .htaccess permissions to override file permissions, which allows remote attackers to obtain the database username and password via a direct ...
CVE-2006-5453
- EPSS 0.81%
- Published 23.10.2006 17:07:00
- Last modified 09.04.2025 00:30:58
Multiple cross-site scripting (XSS) vulnerabilities in Bugzilla 2.18.x before 2.18.6, 2.20.x before 2.20.3, 2.22.x before 2.22.1, and 2.23.x before 2.23.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) page headers us...
- EPSS 1.15%
- Published 23.10.2006 17:07:00
- Last modified 09.04.2025 00:30:58
Bugzilla 2.18.x before 2.18.6, 2.20.x before 2.20.3, 2.22.x before 2.22.1, and 2.23.x before 2.23.3 allow remote attackers to obtain (1) the description of arbitrary attachments by viewing the attachment in "diff" mode in attachment.cgi, and (2) the ...
CVE-2006-5455
- EPSS 0.91%
- Published 23.10.2006 17:07:00
- Last modified 09.04.2025 00:30:58
Cross-site request forgery (CSRF) vulnerability in editversions.cgi in Bugzilla before 2.22.1 and 2.23.x before 2.23.3 allows user-assisted remote attackers to create, modify, or delete arbitrary bug reports via a crafted URL.
CVE-2006-2420
- EPSS 0.69%
- Published 16.05.2006 10:02:00
- Last modified 03.04.2025 01:03:51
Bugzilla 2.20rc1 through 2.20 and 2.21.1, when using RSS 1.0, allows remote attackers to conduct cross-site scripting (XSS) attacks via a title element with HTML encoded sequences such as ">", which are automatically decoded by some RSS readers. ...
CVE-2006-0913
- EPSS 0.82%
- Published 28.02.2006 11:02:00
- Last modified 03.04.2025 01:03:51
SQL injection vulnerability in whineatnews.pl in Bugzilla 2.17 through 2.18.4 and 2.20 allows remote authenticated users with administrative privileges to execute arbitrary SQL commands via the whinedays parameter, as accessible from editparams.cgi.
CVE-2006-0914
- EPSS 0.76%
- Published 28.02.2006 11:02:00
- Last modified 03.04.2025 01:03:51
Bugzilla 2.16.10, 2.17 through 2.18.4, and 2.20 does not properly handle certain characters in the mostfreqthreshold parameter in duplicates.cgi, which allows remote attackers to trigger a SQL error.