Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Bugzilla Data/Mining Directory Insecure Permissions Vulnerability

Bugzilla ships with a data collection script that sets insecure permissions on the data/mining directory each time it is run. This script is intended to be run as a nightly cron job. As a result, this vulnerability may provide a local attacker with a window of opportunity to alter the contents of the data/mining directory.







 

Privacy Statement
Copyright 2008, SecurityFocus