|
All Categories Bugzilla before 2.14.1 allows remote attackers to (1) spoof a user comment via an HTTP request process_bug.cgi using the "who" parameter, instead of the Bugzilla_login cookie, or (2) post a bug as another user by modifying the reporter parameter to enter_bug.cgi, which is passed to post_bug.cgi.Category: WEB-CGI |
IPS Alert Level | ||
Low |
Medium |
High |
Home | Products | Applications | Markets | Support | How to Buy | Channel Partners | Company | ||
Comprehensive Internet Security ® 2003 SonicWALL, Inc. | Privacy Statement |