Vulnerability Name: | CVE-2007-0792 (CCN-32252) | ||||||||
Assigned: | 2007-02-02 | ||||||||
Published: | 2007-02-02 | ||||||||
Updated: | 2018-10-16 | ||||||||
Summary: | The mod_perl initialization script in Bugzilla 2.23.3 does not set the Bugzilla Apache configuration to allow .htaccess permissions to override file permissions, which allows remote attackers to obtain the database username and password via a direct request for the localconfig file. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Fri Feb 02 2007 - 19:54:16 CST Security Advisory for Bugzilla 2.20.3, 2.22.1, and 2.23.3 Source: MITRE Type: CNA CVE-2007-0792 Source: OSVDB Type: UNKNOWN 35862 Source: SREASON Type: UNKNOWN 2222 Source: CCN Type: SECTRACK ID: 1017585 Bugzilla Input Validation Flaw in Atom Feeds Permits Cross-Site Scripting Attacks and Access Control Bug May Disclose Database Password Source: SECTRACK Type: UNKNOWN 1017585 Source: CCN Type: Bugzilla Web site Download :: Bugzilla Source: CONFIRM Type: Vendor Advisory http://www.bugzilla.org/security/2.20.3/ Source: CCN Type: OSVDB ID: 35862 Bugzilla mod_perl Initialization Script Permission Weakness localconfig Direct Request Information Disclosure Source: BUGTRAQ Type: UNKNOWN 20070203 Security Advisory for Bugzilla 2.20.3, 2.22.1, and 2.23.3 Source: BID Type: UNKNOWN 22380 Source: CCN Type: BID-22380 Mozilla Bugzilla HTML Injection And Information disclosure Vulnerabilities Source: VUPEN Type: UNKNOWN ADV-2007-0477 Source: XF Type: UNKNOWN bugzilla-htaccess-information-disclosure(32252) Source: XF Type: UNKNOWN bugzilla-htaccess-information-disclosure(32252) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |