Bugzilla 2.17.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 generates different error messages depending on whether a product exists, which makes it easier for remote attackers to guess product names via unspecified use of the (1) Reports or (2) Duplicates page.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2010-08-16 08:14
Updated : 2010-09-07 22:48
NVD link : CVE-2010-2758
Mitre link : CVE-2010-2758
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
mozilla
- bugzilla