Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Bugzilla Account Creation SQL Injection Vulnerability

Bugzilla is prone to SQL injection attacks. This issue is due to insufficient sanitization of apostrophes (') from e-mail addresses during account creation.

An attacker could exploit this condition to modify the logic of SQL queries, potentially resulting in disclosure of sensitive information or database corruption.







 

Privacy Statement
Copyright 2009, SecurityFocus