CVE Database
/

CVE-2005-2173

Back to search

CVE-2005-2173

Published: Jul 8, 2005

Modified: Aug 7, 2024

PUBLISHED

Description

The Flag::validate and Flag::modify functions in Bugzilla 2.17.1 to 2.18.1 and 2.19.1 to 2.19.3 do not verify that the flag ID is appropriate for the given bug or attachment ID, which allows users to change flags on arbitrary bugs and obtain a bug summary via process_bug.cgi.

VendorProductVersions

n/a

n/a

affected
n/a

References

1014428
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now