[Forgot Password]
Login  Register Subscribe

23631

 
 

115038

 
 

95906

 
 

909

 
 

77986

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2011-0046

Date: (C)2011-01-28   (M)2017-08-18
 
CVSS Score: 6.8Access Vector: NETWORK
Exploitability Subscore: 8.6Access Complexity: MEDIUM
Impact Subscore: 6.4Authentication: NONE
 Confidentiality: PARTIAL
 Integrity: PARTIAL
 Availability: PARTIAL











Multiple cross-site request forgery (CSRF) vulnerabilities in Bugzilla before 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and 4.0.x before 4.0rc2 allow remote attackers to hijack the authentication of arbitrary users for requests related to (1) adding a saved search in buglist.cgi, (2) voting in votes.cgi, (3) sanity checking in sanitycheck.cgi, (4) creating or editing a chart in chart.cgi, (5) column changing in colchange.cgi, and (6) adding, deleting, or approving a quip in quips.cgi.

Reference:
SECUNIA-43033
SECUNIA-43165
BID-45982
OSVDB-70705
OSVDB-70706
OSVDB-70707
OSVDB-70708
OSVDB-70709
OSVDB-70710
ADV-2011-0207
ADV-2011-0271
DSA-2322
FEDORA-2011-0741
FEDORA-2011-0755
bugzilla-unspec-csrf(65003)
http://www.bugzilla.org/security/3.2.9/
https://bugzilla.mozilla.org/show_bug.cgi?id=621090
https://bugzilla.mozilla.org/show_bug.cgi?id=621105
https://bugzilla.mozilla.org/show_bug.cgi?id=621107
https://bugzilla.mozilla.org/show_bug.cgi?id=621108
https://bugzilla.mozilla.org/show_bug.cgi?id=621109
https://bugzilla.mozilla.org/show_bug.cgi?id=621110

CPE    107
cpe:/a:mozilla:bugzilla:2.22:rc1
cpe:/a:mozilla:bugzilla:4.0:rc1
cpe:/a:mozilla:bugzilla:2.20:rc1
cpe:/a:mozilla:bugzilla:2.20:rc2
...
CWE    1
CWE-352
OVAL    1
oval:org.secpod.oval:def:600628

© 2013 SecPod Technologies