BugZilla BugList.CGI HTML Form SQL...

- AV AC AU C I A
发布: 2001-12-29
修订: 2025-04-13

Bugzilla is the bug tracking software package by the Mozilla project. It can be configured to run on Microsoft Windows and various Unix/Linux platforms. A vulnerability exists in the buglist.cgi script which may allow a remote attacker to modify the logic of an SQL query via manipulating an HTML form before submitting it. This is due to lack of input validation of data that is passed to SQL queries.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息