Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2009-1213
Description:Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 3.2 before 3.2.3, 3.3 before 3.3.4, and earlier versions allows remote attackers to hijack the authentication of arbitrary users for requests that use attachment editing.
Test IDs: 1.3.6.1.4.1.25623.1.0.63774   1.3.6.1.4.1.25623.1.0.63773   1.3.6.1.4.1.25623.1.0.100094   1.3.6.1.4.1.25623.1.0.64471  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2009-1213
BugTraq ID: 34308
http://www.securityfocus.com/bid/34308
https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00188.html
https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00191.html
http://secunia.com/advisories/34545
http://secunia.com/advisories/34547
http://secunia.com/advisories/34624
http://www.vupen.com/english/advisories/2009/0887
XForce ISS Database: bugzilla-attachment-csrf(49524)
https://exchange.xforce.ibmcloud.com/vulnerabilities/49524




© 1998-2025 E-Soft Inc. All rights reserved.