Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2012-1969
Description:The get_attachment_link function in Template.pm in Bugzilla 2.x and 3.x before 3.6.10, 3.7.x and 4.0.x before 4.0.7, 4.1.x and 4.2.x before 4.2.2, and 4.3.x before 4.3.2 does not check whether an attachment is private before presenting the attachment description within a public comment, which allows remote attackers to obtain sensitive description information by reading a comment.
Test IDs: 1.3.6.1.4.1.25623.1.0.71514   1.3.6.1.4.1.25623.1.0.864603  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2012-1969
http://www.mandriva.com/security/advisories?name=MDVSA-2013:066
http://secunia.com/advisories/50040




© 1998-2025 E-Soft Inc. All rights reserved.