Логотип exploitDog
bind:CVE-2012-1969
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2012-1969

Количество 4

Количество 4

ubuntu логотип

CVE-2012-1969

больше 13 лет назад

The get_attachment_link function in Template.pm in Bugzilla 2.x and 3.x before 3.6.10, 3.7.x and 4.0.x before 4.0.7, 4.1.x and 4.2.x before 4.2.2, and 4.3.x before 4.3.2 does not check whether an attachment is private before presenting the attachment description within a public comment, which allows remote attackers to obtain sensitive description information by reading a comment.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2012-1969

больше 13 лет назад

The get_attachment_link function in Template.pm in Bugzilla 2.x and 3.x before 3.6.10, 3.7.x and 4.0.x before 4.0.7, 4.1.x and 4.2.x before 4.2.2, and 4.3.x before 4.3.2 does not check whether an attachment is private before presenting the attachment description within a public comment, which allows remote attackers to obtain sensitive description information by reading a comment.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2012-1969

больше 13 лет назад

The get_attachment_link function in Template.pm in Bugzilla 2.x and 3. ...

CVSS2: 4.3
EPSS: Низкий
github логотип

GHSA-qjf6-f5hw-69vh

больше 3 лет назад

The get_attachment_link function in Template.pm in Bugzilla 2.x and 3.x before 3.6.10, 3.7.x and 4.0.x before 4.0.7, 4.1.x and 4.2.x before 4.2.2, and 4.3.x before 4.3.2 does not check whether an attachment is private before presenting the attachment description within a public comment, which allows remote attackers to obtain sensitive description information by reading a comment.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2012-1969

The get_attachment_link function in Template.pm in Bugzilla 2.x and 3.x before 3.6.10, 3.7.x and 4.0.x before 4.0.7, 4.1.x and 4.2.x before 4.2.2, and 4.3.x before 4.3.2 does not check whether an attachment is private before presenting the attachment description within a public comment, which allows remote attackers to obtain sensitive description information by reading a comment.

CVSS2: 4.3
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2012-1969

The get_attachment_link function in Template.pm in Bugzilla 2.x and 3.x before 3.6.10, 3.7.x and 4.0.x before 4.0.7, 4.1.x and 4.2.x before 4.2.2, and 4.3.x before 4.3.2 does not check whether an attachment is private before presenting the attachment description within a public comment, which allows remote attackers to obtain sensitive description information by reading a comment.

CVSS2: 4.3
0%
Низкий
больше 13 лет назад
debian логотип
CVE-2012-1969

The get_attachment_link function in Template.pm in Bugzilla 2.x and 3. ...

CVSS2: 4.3
0%
Низкий
больше 13 лет назад
github логотип
GHSA-qjf6-f5hw-69vh

The get_attachment_link function in Template.pm in Bugzilla 2.x and 3.x before 3.6.10, 3.7.x and 4.0.x before 4.0.7, 4.1.x and 4.2.x before 4.2.2, and 4.3.x before 4.3.2 does not check whether an attachment is private before presenting the attachment description within a public comment, which allows remote attackers to obtain sensitive description information by reading a comment.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу