Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cmv9-xrg2-ccmg

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Bugzilla::Search::build_subselect function in Bugzilla 2.x and 3.x before 3.6.13 and 3.7.x and 4.0.x before 4.0.10 generates different error messages for invalid product queries depending on whether a product exists, which allows remote attackers to discover private product names by using debug mode for a query.

The Bugzilla::Search::build_subselect function in Bugzilla 2.x and 3.x before 3.6.13 and 3.7.x and 4.0.x before 4.0.10 generates different error messages for invalid product queries depending on whether a product exists, which allows remote attackers to discover private product names by using debug mode for a query.

EPSS

Процентиль: 51%
0.00283
Низкий

Дефекты

CWE-200

Связанные уязвимости

ubuntu
почти 13 лет назад

The Bugzilla::Search::build_subselect function in Bugzilla 2.x and 3.x before 3.6.13 and 3.7.x and 4.0.x before 4.0.10 generates different error messages for invalid product queries depending on whether a product exists, which allows remote attackers to discover private product names by using debug mode for a query.

nvd
почти 13 лет назад

The Bugzilla::Search::build_subselect function in Bugzilla 2.x and 3.x before 3.6.13 and 3.7.x and 4.0.x before 4.0.10 generates different error messages for invalid product queries depending on whether a product exists, which allows remote attackers to discover private product names by using debug mode for a query.

debian
почти 13 лет назад

The Bugzilla::Search::build_subselect function in Bugzilla 2.x and 3.x ...

EPSS

Процентиль: 51%
0.00283
Низкий

Дефекты

CWE-200