Korean
<< Back
VID 22230
Severity 40
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The Bugzilla bug-tracking system, according to its version number, has multiple vulnerabilities including SQL injection. Bugzilla is a Web-based bug-tracking system, currently used by a large number of software projects. Multiple vulnerabilities has been reported to exist in this software:

- Two instances of arbitrary SQL injection exploitable only by a privileged user
- One instance where a privileged user may retain privileges that should have been removed
- Two instances of unprivileged access to summaries of restricted data

These bugs are not considered critical, since their impact is quite limited.

* Note: This check solely relied on the version number of Bugzilla in the remote Web server to assess this vulnerability, so this might be a false positive.

* References:
http://www.securiteam.com/unixfocus/6U0041F8UI.html

* Softwares Affected:
Bugzilla prior to version 2.16.4
Bugzilla prior to version 2.17.5
Recommendation Upgrade to the latest version of Bugzilla (2.16.4 or 2.17.5 or later), available from ftp://ftp.mozilla.org/pub/mozilla.org/webtools/
Related URL CVE-2003-1042,CVE-2003-1043,CVE-2003-1044,CVE-2003-1045,CVE-2003-1046 (CVE)
Related URL 8953 (SecurityFocus)
Related URL (ISS)