![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2011-2978 |
Description: | Bugzilla 2.16rc1 through 2.22.7, 3.0.x through 3.3.x, 3.4.x before 3.4.12, 3.5.x, 3.6.x before 3.6.6, 3.7.x, 4.0.x before 4.0.2, and 4.1.x before 4.1.3 does not prevent changes to the confirmation e-mail address (aka old_email field) for e-mail change notifications, which makes it easier for remote attackers to perform arbitrary address changes by leveraging an unattended workstation. |
Test IDs: | 1.3.6.1.4.1.25623.1.0.70264 1.3.6.1.4.1.25623.1.0.70411 |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2011-2978 BugTraq ID: 49042 http://www.securityfocus.com/bid/49042 Debian Security Information: DSA-2322 (Google Search) http://www.debian.org/security/2011/dsa-2322 http://www.osvdb.org/74301 http://secunia.com/advisories/45501 XForce ISS Database: bugzilla-account-sec-bypass(69036) https://exchange.xforce.ibmcloud.com/vulnerabilities/69036 |