Bugzilla Account Creation SQL Injection Vulnerability
BID:5842
Info
Bugzilla Account Creation SQL Injection Vulnerability
| Bugtraq ID: | 5842 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 01 2002 12:00AM |
| Updated: | Oct 01 2002 12:00AM |
| Credit: | This issue was reported in a Bugzilla Security Advisory. |
| Vulnerable: |
Mozilla Bugzilla 2.16 |
| Not Vulnerable: |
Mozilla Bugzilla 2.16.1 Mozilla Bugzilla 2.14.4 Mozilla Bugzilla 2.14.3 Mozilla Bugzilla 2.14.2 Mozilla Bugzilla 2.14.1 Mozilla Bugzilla 2.14 |
Discussion
Bugzilla Account Creation SQL Injection Vulnerability
Bugzilla is prone to SQL injection attacks. This issue is due to insufficient sanitization of apostrophes (') from e-mail addresses during account creation.
An attacker could exploit this condition to modify the logic of SQL queries, potentially resulting in disclosure of sensitive information or database corruption.
Bugzilla is prone to SQL injection attacks. This issue is due to insufficient sanitization of apostrophes (') from e-mail addresses during account creation.
An attacker could exploit this condition to modify the logic of SQL queries, potentially resulting in disclosure of sensitive information or database corruption.
References
Bugzilla Account Creation SQL Injection Vulnerability
References:
References: