Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Bugzilla Bugzilla_Email_Append.pl Arbitrary Command Execution Vulnerability

Bugzilla is a freely available, open source bug tracking software package. It is available for Linux, Unix, and Microsoft Operating Systems.

Under some circumstances, it may be possible to execute arbitrary commands on a Bugzilla server. A user may be able to insert maliciously formatted entries into the Bugzilla database that would be handled by the bugzilla_email_append.pl script. A maliciously formatted entry passed to this script could result in the execution of arbitrary commands.







 

Privacy Statement
Copyright 2009, SecurityFocus