PT-2005-2543 · Mozilla · Bugzilla

Frédéric Buclin

+1

·

Publicado

2005-05-12

·

Atualizado

2017-07-11

·

CVE-2005-1564

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Bugzilla versions 2.10 through 2.18 Bugzilla version 2.19.1 Bugzilla version 2.19.2
Description The issue allows remote authenticated users to enter bugs into products that are closed for bug entry by modifying the URL to specify the name of the product. This is possible due to a flaw in the post bug.cgi script.
Recommendations For Bugzilla versions 2.10 through 2.18, update the post bug.cgi script to properly validate product permissions. For Bugzilla version 2.19.1, restrict access to the post bug.cgi script until a proper fix is applied. For Bugzilla version 2.19.2, consider disabling the post bug.cgi script temporarily to prevent unauthorized bug entry.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-1564

Produtos afetados

Bugzilla