Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2012-4198
Description:The User.get method in Bugzilla/WebService/User.pm in Bugzilla 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1 has a different outcome for a groups request depending on whether a group exists, which allows remote authenticated users to discover private group names by observing whether a call throws an error.
Test IDs: 1.3.6.1.4.1.25623.1.0.72601  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2012-4198
http://www.mandriva.com/security/advisories?name=MDVSA-2013:066




© 1998-2025 E-Soft Inc. All rights reserved.