Title: Bugzilla Closed State Product Bug Entry Creation
Info
Disclosure
May 12, 2005
Discovery
Unknown
Dates
Exploit
May 12, 2005
Solution
Unknown
Description
Bugzilla contains a flaw that may lead to an unauthorized information modification. The issue is triggered when a user correctly guesses the name of a product that should be invisible to them. When this occurs, the user will be able to enter bugs into products that are closed for the bug entry resulting in a loss of integrity.
Classification
Location:
Remote / Network Access
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Public
Disclosure:
Vendor Verified
Solution
Upgrade to version 2.16.9 or higher, version 2.18.1 or higher, or 2.19.3 or higher, as these versions have been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.