Bugzilla Bugzilla_Email_Append.pl Arbitrary Command Execution Vulnerability
BID:5844
Info
Bugzilla Bugzilla_Email_Append.pl Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 5844 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 01 2002 12:00AM |
| Updated: | Oct 01 2002 12:00AM |
| Credit: | This issue was reported in a Bugzilla Security Advisory. |
| Vulnerable: |
Mozilla Bugzilla 2.16 Mozilla Bugzilla 2.14.3 Mozilla Bugzilla 2.14.2 Mozilla Bugzilla 2.14.1 Mozilla Bugzilla 2.14 |
| Not Vulnerable: |
Mozilla Bugzilla 2.16.1 Mozilla Bugzilla 2.14.4 |
Discussion
Bugzilla Bugzilla_Email_Append.pl Arbitrary Command Execution Vulnerability
Bugzilla is a freely available, open source bug tracking software package. It is available for Linux, Unix, and Microsoft Operating Systems.
Under some circumstances, it may be possible to execute arbitrary commands on a Bugzilla server. A user may be able to insert maliciously formatted entries into the Bugzilla database that would be handled by the bugzilla_email_append.pl script. A maliciously formatted entry passed to this script could result in the execution of arbitrary commands.
Bugzilla is a freely available, open source bug tracking software package. It is available for Linux, Unix, and Microsoft Operating Systems.
Under some circumstances, it may be possible to execute arbitrary commands on a Bugzilla server. A user may be able to insert maliciously formatted entries into the Bugzilla database that would be handled by the bugzilla_email_append.pl script. A maliciously formatted entry passed to this script could result in the execution of arbitrary commands.
Exploit / POC
Bugzilla Bugzilla_Email_Append.pl Arbitrary Command Execution Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.