Back to search
CVE-2005-1564
Published: May 14, 2005
Modified: Aug 7, 2024
PUBLISHED
Description
post_bug.cgi in Bugzilla 2.10 through 2.18, 2.19.1, and 2.19.2 allows remote authenticated users to "enter bugs into products that are closed for bug entry" by modifying the URL to specify the name of the product.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://www.bugzilla.org/security/2.16.8/
x_refsource_CONFIRM
20050512 Security Advisory for Bugzilla 2.18, 2.19.2, and 2.16.8
mailing-list
x_refsource_BUGTRAQ
https://bugzilla.mozilla.org/show_bug.cgi?id=287109
x_refsource_CONFIRM
16426
vdb-entry
x_refsource_OSVDB
15338
third-party-advisory
x_refsource_SECUNIA
bugzilla-postbug-weak-security(42797)
vdb-entry
x_refsource_XF
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now