PT-2001-1554 · Mozilla · Bugzilla

Published

2001-05-24

·

Updated

2008-09-10

·

CVE-2001-0329

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Bugzilla version 2.10
Description The issue allows remote attackers to execute arbitrary commands. This can be achieved by including shell metacharacters in a username that is then processed by either the Bugzilla login cookie in the "/post bug.cgi" API endpoint or the who parameter in the "/process bug.cgi" API endpoint.
Recommendations For Bugzilla version 2.10, consider restricting access to the /post bug.cgi and /process bug.cgi API endpoints until a fix is available, and avoid using the who parameter or the Bugzilla login cookie with untrusted input.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-0329

Affected Products

Bugzilla