PT-2001-1554 · Mozilla · Bugzilla
Published
2001-05-24
·
Updated
2008-09-10
·
CVE-2001-0329
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Bugzilla version 2.10
Description
The issue allows remote attackers to execute arbitrary commands. This can be achieved by including shell metacharacters in a
username that is then processed by either the Bugzilla login cookie in the "/post bug.cgi" API endpoint or the who parameter in the "/process bug.cgi" API endpoint.Recommendations
For Bugzilla version 2.10, consider restricting access to the
/post bug.cgi and /process bug.cgi API endpoints until a fix is available, and avoid using the who parameter or the Bugzilla login cookie with untrusted input.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bugzilla