Bugzilla 'localconfig' Information Disclosure Vulnerability
BID:41144
Info
Bugzilla 'localconfig' Information Disclosure Vulnerability
| Bugtraq ID: | 41144 |
| Class: | Configuration Error |
| CVE: |
CVE-2010-0180 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 24 2010 12:00AM |
| Updated: | Jun 24 2010 12:00AM |
| Credit: | Reported by the Vendor |
| Vulnerable: |
Mozilla Bugzilla 3.5.3 Mozilla Bugzilla 3.5.2 Mozilla Bugzilla 3.5.1 Mozilla Bugzilla 3.7 Mozilla Bugzilla 3.6rc1 Mozilla Bugzilla 3.6 |
| Not Vulnerable: |
Mozilla Bugzilla 3.7.1 Mozilla Bugzilla 3.6.1 |
Discussion
Bugzilla 'localconfig' Information Disclosure Vulnerability
Bugzilla is prone to an information-disclosure vulnerability.
Successful exploits may allow attackers to obtain potentially sensitive information that may aid in other attacks.
This issue affects the following:
Bugzilla 3.5.1 through 3.6
Bugzilla 3.7
Bugzilla is prone to an information-disclosure vulnerability.
Successful exploits may allow attackers to obtain potentially sensitive information that may aid in other attacks.
This issue affects the following:
Bugzilla 3.5.1 through 3.6
Bugzilla 3.7
Exploit / POC
Bugzilla 'localconfig' Information Disclosure Vulnerability
An attacker can exploit this issue via a browser.
An attacker can exploit this issue via a browser.
Solution / Fix
Bugzilla 'localconfig' Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Bugzilla 'localconfig' Information Disclosure Vulnerability
References:
References: