CVE-2007-4539Mozilla Bugzilla vulnerability

CWE-2648 documents6 sources
Severity
5.0MEDIUMNVD
EPSS
0.6%
top 31.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 27
Latest updateMay 1

Description

The WebService (XML-RPC) interface in Bugzilla 2.23.3 through 3.0.0 does not enforce permissions for the time-tracking fields of bugs, which allows remote attackers to obtain sensitive information via certain XML-RPC requests, as demonstrated by the (1) Deadline and (2) Estimated Time fields.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDmozilla/bugzilla7 versions+6

Patches

🔴Vulnerability Details

2
GHSA
GHSA-ppwq-7f2c-mmrh: The WebService (XML-RPC) interface in Bugzilla 22022-05-01
CVEList
CVE-2007-4539: The WebService (XML-RPC) interface in Bugzilla 22007-08-27

💥Exploits & PoCs

1
Exploit-DB
Mint Haber Sistemi 2.7 - 'duyuru.asp?id' SQL Injection2007-01-12

📋Vendor Advisories

1
Red Hat
kvm/qemu/xen: Incomplete upstream fix for CVE-2007-13202008-10-29

💬Community

3
Bugzilla
CVE-2008-4539 kvm/qemu/xen: Incomplete upstream fix for CVE-2007-13202008-10-14
Bugzilla
CVE-2007-1320 xen/qemu Cirrus LGD-54XX "bitblt" Heap Overflow [Fedora 8]2008-05-27
Bugzilla
CVE-2007-1320 xen/qemu Cirrus LGD-54XX "bitblt" Heap Overflow [Fedora 9]2008-05-27
CVE-2007-4539 — Mozilla Bugzilla vulnerability | cvebase