Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2009-3165

Overview

Vulnerability Score 7.5 7.5
CVE Id CVE-2009-3165
Last Modified 16 Sep 2009 12:00:00
Published 15 Sep 2009 06:30:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2009-3165

Summary

SQL injection vulnerability in the Bug.create WebService function in Bugzilla 2.23.4 through 3.0.8, 3.1.1 through 3.2.4, and 3.3.1 through 3.4.1 allows remote attackers to execute arbitrary SQL commands via unspecified parameters.

Vulnerable Systems

Application

  • Mozilla Bugzilla 2.23.4

  • Mozilla Bugzilla 3.0

  • Mozilla Bugzilla 3.0.1

  • Mozilla Bugzilla 3.0.2

  • Mozilla Bugzilla 3.0.3

  • Mozilla Bugzilla 3.0.4

  • Mozilla Bugzilla 3.0.5

  • Mozilla Bugzilla 3.0.6

  • Mozilla Bugzilla 3.0.7

  • Mozilla Bugzilla 3.0.8

  • Mozilla Bugzilla 3.1.1

  • Mozilla Bugzilla 3.1.2

  • Mozilla Bugzilla 3.1.3

  • Mozilla Bugzilla 3.1.4

  • Mozilla Bugzilla 3.2

  • Mozilla Bugzilla 3.2.1

  • Mozilla Bugzilla 3.2.2

  • Mozilla Bugzilla 3.2.3

  • Mozilla Bugzilla 3.2.4

  • Mozilla Bugzilla 3.3.1

  • Mozilla Bugzilla 3.3.2

  • Mozilla Bugzilla 3.3.3

  • Mozilla Bugzilla 3.3.4

  • Mozilla Bugzilla 3.4

  • Mozilla Bugzilla 3.4.1


References

BID - 36373

CONFIRM - http://www.bugzilla.org/security/3.0.8/

CONFIRM - https://bugzilla.mozilla.org/show_bug.cgi?id=515191

SECUNIA - 36718


Last Updated: 27 May 2016 10:51:08