Bugzilla showattachment.cgi...

- AV AC AU C I A
发布: 2001-08-29
修订: 2025-04-13

Bugzilla is a free, open source bug tracking and reporting appplication. It allows users to submit bugs, offers a forum for discussing bugs, keeps track of the status of bugs, and can restrict who has access to bug information. An input validation problem exists with Bugzilla. A user of Bugzilla 2.12 may submit an arbitrary bug ID number as an argument to 'showattachment.cgi', potentially disclosing information about "restricted" bugs. This may be a threat if Bugzilla is being used during the development of proprietary sourcecode.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息