{"api_version":"1","generated_at":"2026-07-23T08:57:38+00:00","cve":"CVE-2007-5038","urls":{"html":"https://cve.report/CVE-2007-5038","api":"https://cve.report/api/cve/CVE-2007-5038.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-5038","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-5038"},"summary":{"title":"CVE-2007-5038","description":"The offer_account_by_email function in User.pm in the WebService for Bugzilla before 3.0.2, and 3.1.x before 3.1.2, does not check the value of the createemailregexp parameter, which allows remote attackers to bypass intended restrictions on account creation.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-09-24 00:17:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://secunia.com/advisories/26848","name":"http://secunia.com/advisories/26848","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Bugzilla \"createemailregexp\" Security Bypass Vulnerability - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/26969","name":"http://secunia.com/advisories/26969","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Fedora update for bugzilla - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/480077/100/0/threaded","name":"http://www.securityfocus.com/archive/1/480077/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=299981","name":"https://bugzilla.redhat.com/show_bug.cgi?id=299981","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Bug 299981 – CVE-2007-5038 Security Advisory for Bugzilla 3.0.1 and 3.1.1","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.bugzilla.org/security/3.0.1/","name":"http://www.bugzilla.org/security/3.0.1/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"3.0.1 and 3.1.1 Security Advisory :: Bugzilla :: bugzilla.org","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=395632","name":"https://bugzilla.mozilla.org/show_bug.cgi?id=395632","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"395632 – [SECURITY] XML-RPC WebService Bugzilla::User::offer_account_by_email does not check createemailregexp","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/3200","name":"http://www.vupen.com/english/advisories/2007/3200","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1018719","name":"http://www.securitytracker.com/id?1018719","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Bugzilla WebService Lets Remote Users Create Accounts - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/25725","name":"http://www.securityfocus.com/bid/25725","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Bugzilla User.PM Unauthorized Account Creation Security Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://fedoranews.org/updates/FEDORA-2007-229.shtml","name":"http://fedoranews.org/updates/FEDORA-2007-229.shtml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"404 Not Found","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36692","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36692","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-5038","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-5038","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"5038","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"bugzilla","cpe6":"3.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"5038","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"bugzilla","cpe6":"3.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"5038","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"bugzilla","cpe6":"3.1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"5038","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"bugzilla","cpe6":"3.1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T15:17:28.103Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"FEDORA-2007-2299","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"http://fedoranews.org/updates/FEDORA-2007-229.shtml"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=395632"},{"name":"ADV-2007-3200","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/3200"},{"name":"20070919 Security Advisory for Bugzilla 3.0.1 and 3.1.1","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/480077/100/0/threaded"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=299981"},{"name":"26969","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/26969"},{"name":"1018719","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1018719"},{"name":"26848","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/26848"},{"name":"bugzilla-offeraccount-security-bypass(36692)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36692"},{"name":"25725","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/25725"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.bugzilla.org/security/3.0.1/"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-09-19T00:00:00.000Z","descriptions":[{"lang":"en","value":"The offer_account_by_email function in User.pm in the WebService for Bugzilla before 3.0.2, and 3.1.x before 3.1.2, does not check the value of the createemailregexp parameter, which allows remote attackers to bypass intended restrictions on account creation."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-15T20:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"FEDORA-2007-2299","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"http://fedoranews.org/updates/FEDORA-2007-229.shtml"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=395632"},{"name":"ADV-2007-3200","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/3200"},{"name":"20070919 Security Advisory for Bugzilla 3.0.1 and 3.1.1","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/480077/100/0/threaded"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=299981"},{"name":"26969","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/26969"},{"name":"1018719","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1018719"},{"name":"26848","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/26848"},{"name":"bugzilla-offeraccount-security-bypass(36692)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36692"},{"name":"25725","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/25725"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.bugzilla.org/security/3.0.1/"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-5038","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The offer_account_by_email function in User.pm in the WebService for Bugzilla before 3.0.2, and 3.1.x before 3.1.2, does not check the value of the createemailregexp parameter, which allows remote attackers to bypass intended restrictions on account creation."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"FEDORA-2007-2299","refsource":"FEDORA","url":"http://fedoranews.org/updates/FEDORA-2007-229.shtml"},{"name":"https://bugzilla.mozilla.org/show_bug.cgi?id=395632","refsource":"CONFIRM","url":"https://bugzilla.mozilla.org/show_bug.cgi?id=395632"},{"name":"ADV-2007-3200","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/3200"},{"name":"20070919 Security Advisory for Bugzilla 3.0.1 and 3.1.1","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/480077/100/0/threaded"},{"name":"https://bugzilla.redhat.com/show_bug.cgi?id=299981","refsource":"CONFIRM","url":"https://bugzilla.redhat.com/show_bug.cgi?id=299981"},{"name":"26969","refsource":"SECUNIA","url":"http://secunia.com/advisories/26969"},{"name":"1018719","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1018719"},{"name":"26848","refsource":"SECUNIA","url":"http://secunia.com/advisories/26848"},{"name":"bugzilla-offeraccount-security-bypass(36692)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36692"},{"name":"25725","refsource":"BID","url":"http://www.securityfocus.com/bid/25725"},{"name":"http://www.bugzilla.org/security/3.0.1/","refsource":"CONFIRM","url":"http://www.bugzilla.org/security/3.0.1/"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-5038","datePublished":"2007-09-24T00:00:00.000Z","dateReserved":"2007-09-23T00:00:00.000Z","dateUpdated":"2024-08-07T15:17:28.103Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-09-24 00:17:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:bugzilla:3.0.0:*:*:*:*:*:*:*","matchCriteriaId":"45C36666-518F-4956-816A-940930425955"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:bugzilla:3.0.1:*:*:*:*:*:*:*","matchCriteriaId":"FF2DF96F-E45E-45AF-85E5-E939F923EC1B"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:bugzilla:3.1.0:*:*:*:*:*:*:*","matchCriteriaId":"154EA18F-534C-4095-837D-BB9865D25F23"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:bugzilla:3.1.1:*:*:*:*:*:*:*","matchCriteriaId":"585F05F2-B294-4218-9209-C487B4D2994B"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"5038","Ordinal":"1","Title":"CVE-2007-5038","CVE":"CVE-2007-5038","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"5038","Ordinal":"1","NoteData":"The offer_account_by_email function in User.pm in the WebService for Bugzilla before 3.0.2, and 3.1.x before 3.1.2, does not check the value of the createemailregexp parameter, which allows remote attackers to bypass intended restrictions on account creation.","Type":"Description","Title":"CVE-2007-5038"},{"CveYear":"2007","CveId":"5038","Ordinal":"2","NoteData":"2007-09-23","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"5038","Ordinal":"3","NoteData":"2018-10-15","Type":"Other","Title":"Modified"}]}}}