Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Bugzilla Multiple Remote Vulnerabilities

Bugzilla is prone to multiple remote vulnerabilities, including an HTML-injection issue, a remote command-injection issue, and an information-disclosure issue.

An attacker can exploit these issues to execute arbitrary code and commands with the privileges of the webserver process, steal cookie-based authentication credentials, and obtain sensitive information.

These issues affects Bugzilla 2.20.4, 2.22.2, 3.0, 3.1; prior versions of the 2.20 and 2.22 branches are also affected.







 

Privacy Statement
Copyright 2009, SecurityFocus