Multiple Bugzilla Security Vulnerabilities...

- AV AC AU C I A
发布: 2002-06-08
修订: 2025-04-13

Bugzilla is a freely available, open source bug tracking software package. It is available for Linux, Unix, and Microsoft Operating Systems. Under some circumstances, Bugzilla may leak information about confidential products. The queryhelp.cgi script does not observe any restrictions that may be set on the display of products in the Bugzilla database. Because of this, a user executing the script may be able to gain access to information about confidential products by executing the script.Bugzilla is a freely available, open source bug tracking software package. It is available for Linux, Unix, and Microsoft Operating Systems. Several problems have been discovered in Bugzilla that may allow remote users to gain information through information leakage, or unauthorized access to Bugzilla. The queryhelp.cgi script distributed with Bugzilla could allow remote users to gain access to information products that set as confidential in the Bugzilla database. An attacker may be able to hijack...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息