PT-2006-1957 · Mozilla · Bugzilla

Frédéric Buclin

·

Publicado

2006-02-28

·

Atualizado

2018-10-18

·

CVE-2006-0914

CVSS v2.0

5.5

Média

VetorAV:N/AC:L/Au:S/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions Bugzilla versions 2.16.10, 2.17 through 2.18.4, and 2.20
Description The issue arises from improper handling of certain characters in the mostfreqthreshold parameter in the duplicates.cgi file, allowing remote attackers to trigger a SQL error.
Recommendations For Bugzilla versions 2.16.10, 2.17 through 2.18.4, and 2.20, avoid using the mostfreqthreshold parameter in the duplicates.cgi file until a patch is available. As a temporary workaround, consider restricting access to the duplicates.cgi file to minimize the risk of exploitation.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2006-0914

Produtos afetados

Bugzilla