Bugzilla XSRF Randomization Vulnerability...

- AV AC AU C I A
发布: 2009-02-03
修订: 2025-04-13

Bugzilla 3.2.1, 3.0.7, and 3.3.2, when running under mod_perl, generated insufficiently random numbers, resulting in all random tokens being the same, all CSRF protection being defeated, and the new attachment_base functionality being compromised.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息