Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.70581
Categoría:FreeBSD Local Security Checks
Título:FreeBSD Ports: bugzilla
Resumen:The remote host is missing an update to the system; as announced in the referenced advisory.
Descripción:Summary:
The remote host is missing an update to the system
as announced in the referenced advisory.

Vulnerability Insight:
The following package is affected: bugzilla

CVE-2011-3657
Multiple cross-site scripting (XSS) vulnerabilities in Bugzilla 2.x
and 3.x before 3.4.13, 3.5.x and 3.6.x before 3.6.7, 3.7.x and 4.0.x
before 4.0.3, and 4.1.x through 4.1.3, when debug mode is used, allow
remote attackers to inject arbitrary web script or HTML via vectors
involving a (1) tabular report, (2) graphical report, or (3) new
chart.

CVE-2011-3667
The User.offer_account_by_email WebService method in Bugzilla 2.x and
3.x before 3.4.13, 3.5.x and 3.6.x before 3.6.7, 3.7.x and 4.0.x
before 4.0.3, and 4.1.x through 4.1.3, when createemailregexp is not
empty, does not properly handle user_can_create_account settings,
which allows remote attackers to create user accounts by leveraging a
token contained in an e-mail message.

CVE-2011-3668
Cross-site request forgery (CSRF) vulnerability in post_bug.cgi in
Bugzilla 2.x, 3.x, and 4.x before 4.2rc1 allows remote attackers to
hijack the authentication of arbitrary users for requests that create
bug reports.

CVE-2011-3669
Cross-site request forgery (CSRF) vulnerability in attachment.cgi in
Bugzilla 2.x, 3.x, and 4.x before 4.2rc1 allows remote attackers to
hijack the authentication of arbitrary users for requests that upload
attachments.

Solution:
Update your system with the appropriate patches or
software upgrades.

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2011-3657
Bugtraq: 20111229 Security advisory for Bugzilla 4.2rc1, 4.0.3, 3.6.7 and 3.4.13 (Google Search)
http://archives.neohapsis.com/archives/bugtraq/2011-12/0184.html
Common Vulnerability Exposure (CVE) ID: CVE-2011-3667
XForce ISS Database: bugzilla-createaccount-security-bypass(72042)
https://exchange.xforce.ibmcloud.com/vulnerabilities/72042
Common Vulnerability Exposure (CVE) ID: CVE-2011-3668
http://secunia.com/advisories/47368
Common Vulnerability Exposure (CVE) ID: CVE-2011-3669
CopyrightCopyright (C) 2012 E-Soft Inc.

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.