| VID |
22230 |
| Severity |
40 |
| Port |
80, ... |
| Protocol |
TCP |
| Class |
CGI |
| Detailed Description |
The Bugzilla bug-tracking system, according to its version number, has multiple vulnerabilities including SQL injection. Bugzilla is a Web-based bug-tracking system, currently used by a large number of software projects. Multiple vulnerabilities has been reported to exist in this software:
- Two instances of arbitrary SQL injection exploitable only by a privileged user - One instance where a privileged user may retain privileges that should have been removed - Two instances of unprivileged access to summaries of restricted data
These bugs are not considered critical, since their impact is quite limited.
* Note: This check solely relied on the version number of Bugzilla in the remote Web server to assess this vulnerability, so this might be a false positive.
* References: http://www.securiteam.com/unixfocus/6U0041F8UI.html
* Softwares Affected: Bugzilla prior to version 2.16.4 Bugzilla prior to version 2.17.5 |
| Recommendation |
Upgrade to the latest version of Bugzilla (2.16.4 or 2.17.5 or later), available from ftp://ftp.mozilla.org/pub/mozilla.org/webtools/ |
| Related URL |
CVE-2003-1042,CVE-2003-1043,CVE-2003-1044,CVE-2003-1045,CVE-2003-1046 (CVE) |
| Related URL |
8953 (SecurityFocus) |
| Related URL |
(ISS) |
|