7.5
CVSSv2

CVE-2001-0329

Published: 27/06/2001 Updated: 10/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Bugzilla 2.10 allows remote malicious users to execute arbitrary commands via shell metacharacters in a username that is then processed by (1) the Bugzilla_login cookie in post_bug.cgi, or (2) the who parameter in process_bug.cgi.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla bugzilla 2.4

mozilla bugzilla 2.6

mozilla bugzilla 2.8

mozilla bugzilla 2.10

Exploits

source: wwwsecurityfocuscom/bid/1199/info Bugzilla is a web-based bug-tracking system based on Perl and MySQL It allows people to submit bugs and catalogs them Bugzilla is prone to a vulnerability which may allow remote users to execute arbitrary commands on the target webserver When accepting a bug report, the script "process_bug ...