CVE-2006-5455

Severity

26%

Complexity

49%

Confidentiality

48%

This vulnerability is addressed in the following product release: Mozilla, Bugzilla, 2.22.1 Mozilla, Bugzilla, 2.23.3

Cross-site request forgery (CSRF) vulnerability in editversions.cgi in Bugzilla before 2.22.1 and 2.23.x before 2.23.3 allows user-assisted remote attackers to create, modify, or delete arbitrary bug reports via a crafted URL.

This vulnerability is addressed in the following product release: Mozilla, Bugzilla, 2.22.1 Mozilla, Bugzilla, 2.23.3

CVSS 2.0 Base Score 2.6. CVSS Attack Vector: network. CVSS Attack Complexity: high. CVSS Vector: (AV:N/AC:H/Au:N/C:N/I:P/A:N).

Overview

First reported 18 years ago

2006-10-23 17:07:00

Last updated 6 years ago

2018-10-17 21:43:00

Affected Software

Mozilla Bugzilla

Mozilla Bugzilla 2.23

2.23

Mozilla Bugzilla 2.23.1

2.23.1

Mozilla Bugzilla 2.23.2

2.23.2

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.