Vulnerabilities > CVE-2004-1635
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN nessus
Summary
Bugzilla 2.17.1 through 2.18rc2 and 2.19 from cvs, when using the insidergroup feature, does not sufficiently protect private attachments when there are changes to the metadata, such as filename, description, MIME type, or review flags, which allows remote authenticated users to obtain sensitive information when (1) viewing the bug activity log or (2) receiving bug change notification mails.
Vulnerable Configurations
Nessus
NASL family | CGI abuses |
NASL id | BUGZILLA_AUTH_BYPASS.NASL |
description | The remote Bugzilla bug tracking system, according to its version number, is vulnerable to various flaws that may let an attacker bypass authentication or get access to private bug reports. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 15562 |
published | 2004-10-25 |
reporter | This script is Copyright (C) 2004-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/15562 |
title | Bugzilla < 2.16.7 / 2.18.0rc3 Multiple Information Disclosures |
code |
|
References
- http://marc.info/?l=bugtraq&m=109872095201238&w=2
- http://marc.info/?l=bugtraq&m=109872095201238&w=2
- http://www.securityfocus.com/bid/11511
- http://www.securityfocus.com/bid/11511
- https://bugzilla.mozilla.org/show_bug.cgi?id=250605
- https://bugzilla.mozilla.org/show_bug.cgi?id=250605
- https://bugzilla.mozilla.org/show_bug.cgi?id=253544
- https://bugzilla.mozilla.org/show_bug.cgi?id=253544
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17842
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17842