ID | CVE-2007-4539 | ||||||
Sažetak | The WebService (XML-RPC) interface in Bugzilla 2.23.3 through 3.0.0 does not enforce permissions for the time-tracking fields of bugs, which allows remote attackers to obtain sensitive information via certain XML-RPC requests, as demonstrated by the (1) Deadline and (2) Estimated Time fields. | ||||||
Reference |
|
||||||
CVSS |
|
||||||
Pristup |
|
||||||
Impact |
|
||||||
CVSS vektor | AV:N/AC:L/Au:N/C:P/I:N/A:N | ||||||
Zadnje važnije ažuriranje | 15-10-2018 - 21:35 | ||||||
Objavljeno | 27-08-2007 - 21:17 |