Описание
The offer_account_by_email function in User.pm in the WebService for Bugzilla before 3.0.2, and 3.1.x before 3.1.2, does not check the value of the createemailregexp parameter, which allows remote attackers to bypass intended restrictions on account creation.
Ссылки
- PatchVendor Advisory
- Patch
- Exploit
- PatchVendor Advisory
- Patch
- Exploit
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:mozilla:bugzilla:3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:3.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:3.1.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:3.1.1:*:*:*:*:*:*:*
EPSS
Процентиль: 77%
0.00994
Низкий
7.5 High
CVSS2
Дефекты
CWE-264
Связанные уязвимости
debian
больше 18 лет назад
The offer_account_by_email function in User.pm in the WebService for B ...
github
почти 4 года назад
The offer_account_by_email function in User.pm in the WebService for Bugzilla before 3.0.2, and 3.1.x before 3.1.2, does not check the value of the createemailregexp parameter, which allows remote attackers to bypass intended restrictions on account creation.
EPSS
Процентиль: 77%
0.00994
Низкий
7.5 High
CVSS2
Дефекты
CWE-264