7.5
CVSSv2

CVE-2007-5038

Published: 24/09/2007 Updated: 15/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The offer_account_by_email function in User.pm in the WebService for Bugzilla prior to 3.0.2, and 3.1.x prior to 3.1.2, does not check the value of the createemailregexp parameter, which allows remote malicious users to bypass intended restrictions on account creation.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla bugzilla 3.1.1

mozilla bugzilla 3.0.1

mozilla bugzilla 3.1.0

mozilla bugzilla 3.0.0