CVE-2010-1204
published 2010-06-28CVE-2010-1204: Search.pm in Bugzilla 2.17.1 through 3.2.6, 3.3.1 through 3.4.6, 3.5.1 through 3.6, and 3.7 allows remote attackers to obtain potentially sensitive…
PriorityP419medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.52%
72.0th percentile
Search.pm in Bugzilla 2.17.1 through 3.2.6, 3.3.1 through 3.4.6, 3.5.1 through 3.6, and 3.7 allows remote attackers to obtain potentially sensitive time-tracking information via a crafted search URL, related to a "boolean chart search."
Affected
44 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Bugzilla: Sensitive time-tracking information disclosure via specially-crafted URL
vendor_redhat·2005-09-25·CVSS 5.0
CVE-2010-1204 [MEDIUM] Bugzilla: Sensitive time-tracking information disclosure via specially-crafted URL
Bugzilla: Sensitive time-tracking information disclosure via specially-crafted URL
Search.pm in Bugzilla 2.17.1 through 3.2.6, 3.3.1 through 3.4.6, 3.5.1 through 3.6, and 3.7 allows remote attackers to obtain potentially sensitive time-tracking information via a crafted search URL, related to a "boolean chart search."
GHSA
GHSA-hc22-3vxj-gwr6: Search
ghsa_unreviewed·2022-05-02
CVE-2010-1204 [MEDIUM] GHSA-hc22-3vxj-gwr6: Search
Search.pm in Bugzilla 2.17.1 through 3.2.6, 3.3.1 through 3.4.6, 3.5.1 through 3.6, and 3.7 allows remote attackers to obtain potentially sensitive time-tracking information via a crafted search URL, related to a "boolean chart search."
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-1204 Bugzilla: Sensitive time-tracking information disclosure via specially-crafted URL
bugzilla·2010-06-28·CVSS 5.0
CVE-2010-1204 [MEDIUM] CVE-2010-1204 Bugzilla: Sensitive time-tracking information disclosure via specially-crafted URL
CVE-2010-1204 Bugzilla: Sensitive time-tracking information disclosure via specially-crafted URL
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-1204 to
the following vulnerability:
Search.pm in Bugzilla 2.17.1 through 3.2.6, 3.3.1 through 3.4.6, 3.5.1
through 3.6, and 3.7 allows remote attackers to obtain potentially
sensitive time-tracking information via a crafted search URL, related
to a "boolean chart search."
References:
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1204
[2] http://www.bugzilla.org/security/3.2.6/
[3] https://bugzilla.mozilla.org/show_bug.cgi?id=309952
[4] http://www.securityfocus.com/bid/41141
[5] http://secunia.com/advisories/40300
[6] http://www.vupen.com/english/advisories/2010/1595
Discussion:
The fix for this issue has bee
Bugzilla
CVE-2010-1644 CVE-2010-1645 CVE-2010-2092 Cacti v0.8.7f - three security fixes
bugzilla·2010-05-24·CVSS 4.3
CVE-2010-1644 [MEDIUM] CVE-2010-1644 CVE-2010-1645 CVE-2010-2092 Cacti v0.8.7f - three security fixes
CVE-2010-1644 CVE-2010-1645 CVE-2010-2092 Cacti v0.8.7f - three security fixes
Cacti upstream has released:
[1] http://www.cacti.net/release_notes_0_8_7f.php
latest v0.8.7 version, addressing three security flaws:
[A], MOPS-2010-023: Cacti Graph Viewer SQL Injection Vulnerability
[2] http://php-security.org/2010/05/13/mops-2010-023-cacti-graph-viewer-sql-injection-vulnerability/index.html
[3] http://www.vupen.com/english/advisories/2010/1204
Credit: The vulnerability was discovered by Stefan Esser as part
of the SQL Injection Marathon.
Upstream changeset:
[4] http://svn.cacti.net/viewvc?view=rev&revision=5920
[B], Cross-site scripting issues reported by VUPEN Security
(http://www.vupen.com)
[5] http://www.vupen.com/english/advisories/2010/1203
Credit: Vulnerabilities reported by Moham
http://secunia.com/advisories/40300http://www.bugzilla.org/security/3.2.6/http://www.securityfocus.com/bid/41141http://www.vupen.com/english/advisories/2010/1595https://bugzilla.mozilla.org/show_bug.cgi?id=309952http://secunia.com/advisories/40300http://www.bugzilla.org/security/3.2.6/http://www.securityfocus.com/bid/41141http://www.vupen.com/english/advisories/2010/1595https://bugzilla.mozilla.org/show_bug.cgi?id=309952
2010-06-28
Published