cbcvebase.
CVE-2009-3125
published 2009-09-15

CVE-2009-3125: SQL injection vulnerability in the Bug.search WebService function in Bugzilla 3.3.2 through 3.4.1, and 3.5, allows remote attackers to execute arbitrary SQL…

high7.5CVSS 3.1
AVNACLAuNCPIPAP
SQL injection vulnerability in the Bug.search WebService function in Bugzilla 3.3.2 through 3.4.1, and 3.5, allows remote attackers to execute arbitrary SQL commands via unspecified parameters.

Affected

6 ranges
VendorProductVersion rangeFixed in
mozillabugzilla
mozillabugzilla
mozillabugzilla
mozillabugzilla
mozillabugzilla
mozillabugzilla