Bugzilla before 2.14 includes the username and password in URLs, which could allow attackers to gain privileges by reading the information from the web server logs, or by shoulder-surfing and observing the web browsers location bar.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Bugzilla | Mozilla | 2.10 | 2.10 |
Bugzilla | Mozilla | 2.6 | 2.6 |
Bugzilla | Mozilla | 2.4 | 2.4 |
Bugzilla | Mozilla | 2.12 | 2.12 |
Bugzilla | Mozilla | 2.8 | 2.8 |
Bugzilla | Mozilla | 2.14 | 2.14 |