CVE-2008-4437
published 2008-10-03CVE-2008-4437: Directory traversal vulnerability in importxml.pl in Bugzilla before 2.22.5, and 3.x before 3.0.5, when --attach_path is enabled, allows remote attackers to…
PriorityP340high7.1CVSS 2.0
AVNACMAuNCCINAN
EXPLOIT
EPSS
5.64%
92.0th percentile
Directory traversal vulnerability in importxml.pl in Bugzilla before 2.22.5, and 3.x before 3.0.5, when --attach_path is enabled, allows remote attackers to read arbitrary files via an XML file with a .. (dot dot) in the data element.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
CVSS provenance
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:C/I:N/A:N
vendor_redhat7.1HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
bugzilla directory traversal flaw
vendor_redhat·2008-10-06·CVSS 7.1
CVE-2008-4437 [HIGH] bugzilla directory traversal flaw
bugzilla directory traversal flaw
Directory traversal vulnerability in importxml.pl in Bugzilla before 2.22.5, and 3.x before 3.0.5, when --attach_path is enabled, allows remote attackers to read arbitrary files via an XML file with a .. (dot dot) in the data element.
GHSA
GHSA-ph4j-q265-3h3m: Directory traversal vulnerability in importxml
ghsa_unreviewed·2022-05-02
CVE-2008-4437 [HIGH] CWE-22 GHSA-ph4j-q265-3h3m: Directory traversal vulnerability in importxml
Directory traversal vulnerability in importxml.pl in Bugzilla before 2.22.5, and 3.x before 3.0.5, when --attach_path is enabled, allows remote attackers to read arbitrary files via an XML file with a .. (dot dot) in the data element.
No detection rules found.
Bugzilla
CVE-2008-4437 CVE-2008-6098, CVE-2009-048[13456] bugzilla: multiple issues [F9]
bugzilla·2009-02-09·CVSS 7.1
CVE-2008-4437 [HIGH] CVE-2008-4437 CVE-2008-6098, CVE-2009-048[13456] bugzilla: multiple issues [F9]
CVE-2008-4437 CVE-2008-6098, CVE-2009-048[13456] bugzilla: multiple issues [F9]
F9 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
You can eventually use the following link to create the update request:
https://admin.fedoraproject.org/updates/new/?request=Stable&type_=security&release=Fedora%209&bugs=484757,
---
Correct update submission URL is:
https://admin.fedoraproject.org/updates/new/?request=Stable&type_=security&bugs=484757,CVE-2008-6098,CVE-2009-0481,CVE-2009-0482,CVE-2009-0483,CVE-2009-0484,CVE-2009-0485,CVE-2009-0486
---
*** Bug 465958 has been marked as a duplicate of this bug. ***
---
CVE-2008-4437 fixed in upstream 3.0.5 is still unfixed too, adding it to this tracking bug, u
Bugzilla
CVE-2008-4437 CVE-2008-6098 CVE-2008-048[13456] bugzilla: multiple issues [Fdevel]
bugzilla·2009-02-09·CVSS 7.1
CVE-2008-4437 [HIGH] CVE-2008-4437 CVE-2008-6098 CVE-2008-048[13456] bugzilla: multiple issues [Fdevel]
CVE-2008-4437 CVE-2008-6098 CVE-2008-048[13456] bugzilla: multiple issues [Fdevel]
Fdevel tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
Adding also CVE-2008-4437, which was upstream in 3.0.5.
---
This package has changed ownership in the Fedora Package Database. Reassigning to the new owner of this component.
---
I am going upgrade to 3.0.8 in F-10 and F-9 and to 3.2.2 into rawhide.
*** This bug has been marked as a duplicate of bug 474250 ***
---
CVE-2009-0482 was not fixed upstream in 3.0.x
---
going to 3.2.2 soon
Bugzilla
CVE-2008-4437 CVE-2008-6098, CVE-2009-048[13456] bugzilla: multiple issues [F10]
bugzilla·2009-02-09·CVSS 7.1
CVE-2008-4437 [HIGH] CVE-2008-4437 CVE-2008-6098, CVE-2009-048[13456] bugzilla: multiple issues [F10]
CVE-2008-4437 CVE-2008-6098, CVE-2009-048[13456] bugzilla: multiple issues [F10]
F10 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
You can eventually use the following link to create the update request:
https://admin.fedoraproject.org/updates/new/?request=Stable&type_=security&release=Fedora%2010&bugs=484756,
---
Correct update submission URL is:
https://admin.fedoraproject.org/updates/new/?request=Stable&type_=security&bugs=484756,CVE-2008-6098,CVE-2009-0481,CVE-2009-0482,CVE-2009-0483,CVE-2009-0484,CVE-2009-0485,CVE-2009-0486
---
*** Bug 465959 has been marked as a duplicate of this bug. ***
---
CVE-2008-4437 fixed in upstream 3.0.5 is still unfixed too, adding it to this tracking bug
Bugzilla
CVE-2008-4437 bugzilla directory traversal flaw [F9]
bugzilla·2008-10-07·CVSS 7.1
CVE-2008-4437 [HIGH] CVE-2008-4437 bugzilla directory traversal flaw [F9]
CVE-2008-4437 bugzilla directory traversal flaw [F9]
F9 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
You can eventually use the following link to create the update request:
https://admin.fedoraproject.org/updates/new/?request=Stable&type_=security&release=Fedora%209&bugs=465958,
---
Note that this is fixed in Bugzilla 3.0.5 (bug #466077)
---
Merge with other security tracking bug for bugzilla/F9.
*** This bug has been marked as a duplicate of bug 484757 ***
Bugzilla
CVE-2008-4437 bugzilla directory traversal flaw
bugzilla·2008-10-07·CVSS 7.1
CVE-2008-4437 [HIGH] CVE-2008-4437 bugzilla directory traversal flaw
CVE-2008-4437 bugzilla directory traversal flaw
Directory traversal vulnerability in importxml.pl in Bugzilla before 2.22.5, and 3.x before 3.0.5, when --attach_path is enabled, allows remote attackers to read arbitrary files via an XML file with a .. (dot dot) in the data element.
https://bugzilla.mozilla.org/show_bug.cgi?id=437169
http://www.bugzilla.org/security/2.22.4/
http://www.securityfocus.com/bid/30661
http://www.frsirt.com/english/advisories/2008/2344
http://secunia.com/advisories/31444
Discussion:
Created bugzilla tracking bugs for this issue
CVE-2008-4437 Affects: F8 [bug #465957]
CVE-2008-4437 Affects: F9 [bug #465958]
CVE-2008-4437 Affects: Fdevel [bug #465959]
---
bugzilla-3.2.2-2.fc9 has been submitted as an update for Fedora 9.
http://admin.fedoraproject.org/updates
Bugzilla
CVE-2008-4437 bugzilla directory traversal flaw [Fdevel]
bugzilla·2008-10-07·CVSS 7.1
CVE-2008-4437 [HIGH] CVE-2008-4437 bugzilla directory traversal flaw [Fdevel]
CVE-2008-4437 bugzilla directory traversal flaw [Fdevel]
Fdevel tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
Note that this is fixed in Bugzilla 3.0.5 (bug #466077)
---
This bug appears to have been reported against 'rawhide' during the Fedora 10 development cycle.
Changing version to '10'.
More information and reason for this action is here:
http://fedoraproject.org/wiki/BugZappers/HouseKeeping
---
Merge with other security tracking bug for bugzilla/F10.
*** This bug has been marked as a duplicate of bug 484756 ***
Bugzilla
CVE-2008-4437 bugzilla directory traversal flaw [F8]
bugzilla·2008-10-07·CVSS 7.1
CVE-2008-4437 [HIGH] CVE-2008-4437 bugzilla directory traversal flaw [F8]
CVE-2008-4437 bugzilla directory traversal flaw [F8]
F8 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
You can eventually use the following link to create the update request:
https://admin.fedoraproject.org/updates/new/?request=Stable&type_=security&release=Fedora%208&bugs=465957,
---
Note that this is fixed in Bugzilla 3.0.5 (bug #466077)
---
This message is a reminder that Fedora 8 is nearing its end of life.
Approximately 30 (thirty) days from now Fedora will stop maintaining
and issuing updates for Fedora 8. It is Fedora's policy to close all
bug reports from releases that are no longer maintained. At that time
this bug will be closed as WONTFIX if it remains open with a Fedora
'version
http://secunia.com/advisories/31444http://secunia.com/advisories/34361http://www.bugzilla.org/security/2.22.4/http://www.securityfocus.com/bid/30661http://www.securitytracker.com/id?1020668http://www.vupen.com/english/advisories/2008/2344https://bugzilla.mozilla.org/show_bug.cgi?id=437169https://exchange.xforce.ibmcloud.com/vulnerabilities/44407https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00664.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-March/msg00687.htmlhttp://secunia.com/advisories/31444http://secunia.com/advisories/34361http://www.bugzilla.org/security/2.22.4/http://www.securityfocus.com/bid/30661http://www.securitytracker.com/id?1020668http://www.vupen.com/english/advisories/2008/2344https://bugzilla.mozilla.org/show_bug.cgi?id=437169https://exchange.xforce.ibmcloud.com/vulnerabilities/44407https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00664.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-March/msg00687.html
2008-10-03
Published