Vulnerability Name: | CVE-2006-5455 (CCN-29618) | ||||||||
Assigned: | 2006-10-15 | ||||||||
Published: | 2006-10-15 | ||||||||
Updated: | 2018-10-17 | ||||||||
Summary: | Cross-site request forgery (CSRF) vulnerability in editversions.cgi in Bugzilla before 2.22.1 and 2.23.x before 2.23.3 allows user-assisted remote attackers to create, modify, or delete arbitrary bug reports via a crafted URL. This vulnerability is addressed in the following product release: Mozilla, Bugzilla, 2.22.1 Mozilla, Bugzilla, 2.23.3 | ||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 2.6 Low (CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N) 1.9 Low (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
1.9 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Data Manipulation | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Sun Oct 15 2006 - 05:02:20 CDT Security Advisory for Bugzilla 2.18.5, 2.20.2, 2.22, and 2.23.2 Source: MITRE Type: CNA CVE-2006-5455 Source: CCN Type: SA22409 Bugzilla Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 22409 Source: SECUNIA Type: UNKNOWN 22790 Source: GENTOO Type: UNKNOWN GLSA-200611-04 Source: SREASON Type: UNKNOWN 1760 Source: CCN Type: Bugzilla Web site 2.18.5, 2.20.2, 2.22, and 2.23.2 Security Advisory Source: CONFIRM Type: UNKNOWN http://www.bugzilla.org/security/2.18.5/ Source: CCN Type: GLSA-200611-04 Bugzilla: Multiple Vulnerabilities Source: OSVDB Type: UNKNOWN 29548 Source: CCN Type: OSVDB ID: 29548 Bugzilla Crafted URL User-complicit Arbitrary Command Execution Source: BUGTRAQ Type: UNKNOWN 20061015 Security Advisory for Bugzilla 2.18.5, 2.20.2, 2.22, and 2.23.2 Source: BID Type: UNKNOWN 20538 Source: CCN Type: BID-20538 Mozilla Bugzilla Multiple Input Validation and Information disclosure Vulnerabilities Source: VUPEN Type: UNKNOWN ADV-2006-4035 Source: CONFIRM Type: Patch https://bugzilla.mozilla.org/show_bug.cgi?id=281181 Source: XF Type: UNKNOWN bugzilla-url-modify-configuration(29618) Source: XF Type: UNKNOWN bugzilla-url-modify-configuration(29618) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |