CVE-2005-3138
published 2005-10-05CVE-2005-3138: Bugzilla 2.18rc1 through 2.18.3, 2.19 through 2.20rc2, and 2.21 allows remote attackers to obtain sensitive information such as the list of installed products…
PriorityP413medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.14%
63.3th percentile
Bugzilla 2.18rc1 through 2.18.3, 2.19 through 2.20rc2, and 2.21 allows remote attackers to obtain sensitive information such as the list of installed products via the config.cgi file, which is accessible even when the requirelogin parameter is set.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://marc.info/?l=bugtraq&m=112818466125484&w=2http://secunia.com/advisories/17030/http://www.bugzilla.org/security/2.18.4/http://www.securityfocus.com/bid/14995https://exchange.xforce.ibmcloud.com/vulnerabilities/22490http://marc.info/?l=bugtraq&m=112818466125484&w=2http://secunia.com/advisories/17030/http://www.bugzilla.org/security/2.18.4/http://www.securityfocus.com/bid/14995https://exchange.xforce.ibmcloud.com/vulnerabilities/22490
2005-10-05
Published