Логотип exploitDog
bind:CVE-2011-3667
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2011-3667

Количество 4

Количество 4

ubuntu логотип

CVE-2011-3667

около 14 лет назад

The User.offer_account_by_email WebService method in Bugzilla 2.x and 3.x before 3.4.13, 3.5.x and 3.6.x before 3.6.7, 3.7.x and 4.0.x before 4.0.3, and 4.1.x through 4.1.3, when createemailregexp is not empty, does not properly handle user_can_create_account settings, which allows remote attackers to create user accounts by leveraging a token contained in an e-mail message.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2011-3667

около 14 лет назад

The User.offer_account_by_email WebService method in Bugzilla 2.x and 3.x before 3.4.13, 3.5.x and 3.6.x before 3.6.7, 3.7.x and 4.0.x before 4.0.3, and 4.1.x through 4.1.3, when createemailregexp is not empty, does not properly handle user_can_create_account settings, which allows remote attackers to create user accounts by leveraging a token contained in an e-mail message.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2011-3667

около 14 лет назад

The User.offer_account_by_email WebService method in Bugzilla 2.x and ...

CVSS2: 6.8
EPSS: Низкий
github логотип

GHSA-j234-73mf-fxmv

больше 3 лет назад

The User.offer_account_by_email WebService method in Bugzilla 2.x and 3.x before 3.4.13, 3.5.x and 3.6.x before 3.6.7, 3.7.x and 4.0.x before 4.0.3, and 4.1.x through 4.1.3, when createemailregexp is not empty, does not properly handle user_can_create_account settings, which allows remote attackers to create user accounts by leveraging a token contained in an e-mail message.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2011-3667

The User.offer_account_by_email WebService method in Bugzilla 2.x and 3.x before 3.4.13, 3.5.x and 3.6.x before 3.6.7, 3.7.x and 4.0.x before 4.0.3, and 4.1.x through 4.1.3, when createemailregexp is not empty, does not properly handle user_can_create_account settings, which allows remote attackers to create user accounts by leveraging a token contained in an e-mail message.

CVSS2: 6.8
0%
Низкий
около 14 лет назад
nvd логотип
CVE-2011-3667

The User.offer_account_by_email WebService method in Bugzilla 2.x and 3.x before 3.4.13, 3.5.x and 3.6.x before 3.6.7, 3.7.x and 4.0.x before 4.0.3, and 4.1.x through 4.1.3, when createemailregexp is not empty, does not properly handle user_can_create_account settings, which allows remote attackers to create user accounts by leveraging a token contained in an e-mail message.

CVSS2: 6.8
0%
Низкий
около 14 лет назад
debian логотип
CVE-2011-3667

The User.offer_account_by_email WebService method in Bugzilla 2.x and ...

CVSS2: 6.8
0%
Низкий
около 14 лет назад
github логотип
GHSA-j234-73mf-fxmv

The User.offer_account_by_email WebService method in Bugzilla 2.x and 3.x before 3.4.13, 3.5.x and 3.6.x before 3.6.7, 3.7.x and 4.0.x before 4.0.3, and 4.1.x through 4.1.3, when createemailregexp is not empty, does not properly handle user_can_create_account settings, which allows remote attackers to create user accounts by leveraging a token contained in an e-mail message.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу