Информационная безопасность
[RU] switch to
English Version



CVECVE-2009-3165
СтатусCandidate
ОписаниеSQL injection vulnerability in the Bug.create WebService function in Bugzilla 2.23.4 through 3.0.8, 3.1.1 through 3.2.4, and 3.3.1 through 3.4.1 allows remote attackers to execute arbitrary SQL commands via unspecified parameters.
ВажностьHigh
CVSS score7,5
CVSS vector(AV:N/AC:L/Au:N/C:P/I:P/A:P)
PhaseAssigned (16.09.2009)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-3165
ReferencesBID : 36373
 CONFIRM : http://www.bugzilla.org/security/3.0.8/
 CONFIRM : https://bugzilla.mozilla.org/show_bug.cgi?id=515191
 SECUNIA : 36718

О сайте | Условия использования
© SecurityVulns, 3APA3A, Владимир Дубровин
Нижний Новгород

 
 



Rating@Mail.ru
test server