CVE-2008-2104

The WebService in Bugzilla 3.1.3 allows remote authenticated users without canconfirm privileges to create NEW or ASSIGNED bug entries via a request to the XML-RPC interface, which bypasses the canconfirm check.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:mozilla:bugzilla:3.1.3:*:*:*:*:*:*:*

Information

Published : 2008-05-07 13:20

Updated : 2017-08-07 18:30


NVD link : CVE-2008-2104

Mitre link : CVE-2008-2104


JSON object : View

CWE
CWE-264

Permissions, Privileges, and Access Controls

Advertisement

dedicated server usa

Products Affected

mozilla

  • bugzilla