CVE-2007-5038
published 2007-09-24CVE-2007-5038: The offer_account_by_email function in User.pm in the WebService for Bugzilla before 3.0.2, and 3.1.x before 3.1.2, does not check the value of the…
PriorityP335high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.96%
78.0th percentile
The offer_account_by_email function in User.pm in the WebService for Bugzilla before 3.0.2, and 3.1.x before 3.1.2, does not check the value of the createemailregexp parameter, which allows remote attackers to bypass intended restrictions on account creation.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://fedoranews.org/updates/FEDORA-2007-229.shtmlhttp://secunia.com/advisories/26848http://secunia.com/advisories/26969http://www.bugzilla.org/security/3.0.1/http://www.securityfocus.com/archive/1/480077/100/0/threadedhttp://www.securityfocus.com/bid/25725http://www.securitytracker.com/id?1018719http://www.vupen.com/english/advisories/2007/3200https://bugzilla.mozilla.org/show_bug.cgi?id=395632https://bugzilla.redhat.com/show_bug.cgi?id=299981https://exchange.xforce.ibmcloud.com/vulnerabilities/36692http://fedoranews.org/updates/FEDORA-2007-229.shtmlhttp://secunia.com/advisories/26848http://secunia.com/advisories/26969http://www.bugzilla.org/security/3.0.1/http://www.securityfocus.com/archive/1/480077/100/0/threadedhttp://www.securityfocus.com/bid/25725http://www.securitytracker.com/id?1018719http://www.vupen.com/english/advisories/2007/3200https://bugzilla.mozilla.org/show_bug.cgi?id=395632https://bugzilla.redhat.com/show_bug.cgi?id=299981https://exchange.xforce.ibmcloud.com/vulnerabilities/36692
2007-09-24
Published