Korean
<< Back
VID 21384
Severity 30
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The Bugzilla bug-tracking system, according to its version number, has multiple security vulnerabilities. Bugzilla is a Web-based bug-tracking system, based on Perl and MySQL. Bugzilla versions 2.9 through 2.18rc2 and version 2.19 (cvs) are vulnerable to various flaws that may allow a remote attacker to view private comments and attachments or to perform an unauthorized bug change.

* Note: This check solely relied on the version number of Bugzilla in the remote Web server to assess this vulnerability, so this might be a false positive.

* References:
http://archives.neohapsis.com/archives/bugtraq/2004-10/0251.html

* Platforms Affected:
Mozilla Project, Bugzilla 2.9 to 2.18rc2
Mozilla Project, Bugzilla 2.19 (cvs)
Any operating system Any version
Recommendation Upgrade to the latest version of Bugzilla (2.16.7 or 2.18rc3, or 2.19.1(cvs) or later), available from the Bugzilla Download Web site at http://www.bugzilla.org/download/
Related URL CVE-2004-1633,CVE-2004-1634 (CVE)
Related URL 11511 (SecurityFocus)
Related URL 17840,17841 (ISS)