Vulnerability Name: | CVE-2007-5038 (CCN-36692) | ||||||||
Assigned: | 2007-09-18 | ||||||||
Published: | 2007-09-18 | ||||||||
Updated: | 2018-10-15 | ||||||||
Summary: | The offer_account_by_email function in User.pm in the WebService for Bugzilla before 3.0.2, and 3.1.x before 3.1.2, does not check the value of the createemailregexp parameter, which allows remote attackers to bypass intended restrictions on account creation. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2007-5038 Source: FEDORA Type: UNKNOWN FEDORA-2007-2299 Source: CCN Type: SA26848 Bugzilla "createemailregexp" Security Bypass Vulnerability Source: SECUNIA Type: Patch, Vendor Advisory 26848 Source: SECUNIA Type: UNKNOWN 26969 Source: CCN Type: SECTRACK ID: 1018719 Bugzilla WebService Lets Remote Users Create Accounts Source: CCN Type: Bugzilla Web site 3.0.1 and 3.1.1 Security Advisory Source: CONFIRM Type: Patch http://www.bugzilla.org/security/3.0.1/ Source: CCN Type: OSVDB ID: 37200 Bugzilla WebService/User.pm offer_account_by_email() Function createemailregexp Arbitrary Account Creation Source: BUGTRAQ Type: UNKNOWN 20070919 Security Advisory for Bugzilla 3.0.1 and 3.1.1 Source: BID Type: UNKNOWN 25725 Source: CCN Type: BID-25725 Bugzilla User.PM Unauthorized Account Creation Security Bypass Vulnerability Source: SECTRACK Type: UNKNOWN 1018719 Source: VUPEN Type: UNKNOWN ADV-2007-3200 Source: CONFIRM Type: Exploit https://bugzilla.mozilla.org/show_bug.cgi?id=395632 Source: CONFIRM Type: UNKNOWN https://bugzilla.redhat.com/show_bug.cgi?id=299981 Source: XF Type: UNKNOWN bugzilla-offeraccount-security-bypass(36692) Source: XF Type: UNKNOWN bugzilla-offeraccount-security-bypass(36692) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |