5
CVSSv2

CVE-2005-3138

Published: 05/10/2005 Updated: 11/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Bugzilla 2.18rc1 up to and including 2.18.3, 2.19 up to and including 2.20rc2, and 2.21 allows remote malicious users to obtain sensitive information such as the list of installed products via the config.cgi file, which is accessible even when the requirelogin parameter is set.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla bugzilla 2.18.1

mozilla bugzilla 2.18.2

mozilla bugzilla 2.19.2

mozilla bugzilla 2.19.3

mozilla bugzilla 2.18.3

mozilla bugzilla 2.18

mozilla bugzilla 2.20

mozilla bugzilla 2.21

mozilla bugzilla 2.19

mozilla bugzilla 2.19.1