Directory traversal vulnerability in importxml.pl in Bugzilla before 2.22.5, and 3.x before 3.0.5, when --attach_path is enabled, allows remote attackers to read arbitrary files via an XML file with a .. (dot dot) in the data element.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2008-10-03 15:22
Updated : 2017-08-07 18:32
NVD link : CVE-2008-4437
Mitre link : CVE-2008-4437
JSON object : View
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Products Affected
mozilla
- bugzilla