Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Bugzilla User.PM Unauthorized Account Creation Security Bypass Vulnerability

Bugzilla is prone to a security-bypass vulnerability because it fails to adequately validate user-supplied input.

Attackers can exploit this issue to create Bugzilla user accounts on computers that also have the 'SOAP::Lite' Perl module installed.

NOTE: The application is vulnerable even if account creation has been disabled.

Versions prior to Bugzilla 3.0.2 and 3.1.2 are vulnerable.







 

Privacy Statement
Copyright 2009, SecurityFocus