4.3
CVSSv2

CVE-2012-0465

Published: 27/04/2012 Updated: 14/08/2012
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Bugzilla 3.5.x and 3.6.x prior to 3.6.9, 3.7.x and 4.0.x prior to 4.0.6, and 4.1.x and 4.2.x prior to 4.2.1, when the inbound_proxies option is enabled, does not properly validate the X-Forwarded-For HTTP header, which allows remote malicious users to bypass the lockout policy via a series of authentication requests with (1) different IP address strings in this header or (2) a long string in this header.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla bugzilla 3.5.3

mozilla bugzilla 3.5.2

mozilla bugzilla 3.5.1

mozilla bugzilla 3.6.4

mozilla bugzilla 3.6.5

mozilla bugzilla 4.0.4

mozilla bugzilla 4.0.1

mozilla bugzilla 3.6.1

mozilla bugzilla 3.6.0

mozilla bugzilla 3.6.3

mozilla bugzilla 3.7.1

mozilla bugzilla 4.0.5

mozilla bugzilla 4.1.3

mozilla bugzilla 3.6.2

mozilla bugzilla 3.6.6

mozilla bugzilla 3.7.2

mozilla bugzilla 3.7.3

mozilla bugzilla 4.1.1

mozilla bugzilla 4.1.2

mozilla bugzilla 3.6.7

mozilla bugzilla 3.6.8

mozilla bugzilla 4.0.2

mozilla bugzilla 4.0.3

mozilla bugzilla 4.2