![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2007-5038 |
Description: | The offer_account_by_email function in User.pm in the WebService for Bugzilla before 3.0.2, and 3.1.x before 3.1.2, does not check the value of the createemailregexp parameter, which allows remote attackers to bypass intended restrictions on account creation. |
Test IDs: | 1.3.6.1.4.1.25623.1.0.59806 1.3.6.1.4.1.25623.1.0.861402 1.3.6.1.4.1.25623.1.0.58798 |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2007-5038 BugTraq ID: 25725 http://www.securityfocus.com/bid/25725 Bugtraq: 20070919 Security Advisory for Bugzilla 3.0.1 and 3.1.1 (Google Search) http://www.securityfocus.com/archive/1/480077/100/0/threaded http://fedoranews.org/updates/FEDORA-2007-229.shtml http://www.securitytracker.com/id?1018719 http://secunia.com/advisories/26848 http://secunia.com/advisories/26969 http://www.vupen.com/english/advisories/2007/3200 XForce ISS Database: bugzilla-offeraccount-security-bypass(36692) https://exchange.xforce.ibmcloud.com/vulnerabilities/36692 |