Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2011-3667
Description:The User.offer_account_by_email WebService method in Bugzilla 2.x and 3.x before 3.4.13, 3.5.x and 3.6.x before 3.6.7, 3.7.x and 4.0.x before 4.0.3, and 4.1.x through 4.1.3, when createemailregexp is not empty, does not properly handle user_can_create_account settings, which allows remote attackers to create user accounts by leveraging a token contained in an e-mail message.
Test IDs: 1.3.6.1.4.1.25623.1.0.70581  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2011-3667
Bugtraq: 20111229 Security advisory for Bugzilla 4.2rc1, 4.0.3, 3.6.7 and 3.4.13 (Google Search)
http://archives.neohapsis.com/archives/bugtraq/2011-12/0184.html
XForce ISS Database: bugzilla-createaccount-security-bypass(72042)
https://exchange.xforce.ibmcloud.com/vulnerabilities/72042




© 1998-2025 E-Soft Inc. All rights reserved.