CVE Vulnerabilities

CVE-2005-1564

Published: May 12, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

post_bug.cgi in Bugzilla 2.10 through 2.18, 2.19.1, and 2.19.2 allows remote authenticated users to enter bugs into products that are closed for bug entry by modifying the URL to specify the name of the product.

Affected Software

NameVendorStart VersionEnd Version
BugzillaMozilla2.10 (including)2.10 (including)
BugzillaMozilla2.12 (including)2.12 (including)
BugzillaMozilla2.14 (including)2.14 (including)
BugzillaMozilla2.14.1 (including)2.14.1 (including)
BugzillaMozilla2.14.2 (including)2.14.2 (including)
BugzillaMozilla2.14.3 (including)2.14.3 (including)
BugzillaMozilla2.14.4 (including)2.14.4 (including)
BugzillaMozilla2.14.5 (including)2.14.5 (including)
BugzillaMozilla2.16 (including)2.16 (including)
BugzillaMozilla2.16.1 (including)2.16.1 (including)
BugzillaMozilla2.16.2 (including)2.16.2 (including)
BugzillaMozilla2.16.3 (including)2.16.3 (including)
BugzillaMozilla2.16.4 (including)2.16.4 (including)
BugzillaMozilla2.16.5 (including)2.16.5 (including)
BugzillaMozilla2.17 (including)2.17 (including)
BugzillaMozilla2.17.1 (including)2.17.1 (including)
BugzillaMozilla2.17.3 (including)2.17.3 (including)
BugzillaMozilla2.17.4 (including)2.17.4 (including)
BugzillaMozilla2.17.5 (including)2.17.5 (including)
BugzillaMozilla2.17.6 (including)2.17.6 (including)
BugzillaMozilla2.17.7 (including)2.17.7 (including)
BugzillaMozilla2.18-rc1 (including)2.18-rc1 (including)
BugzillaMozilla2.18-rc2 (including)2.18-rc2 (including)
BugzillaMozilla2.19.1 (including)2.19.1 (including)
BugzillaMozilla2.19.2 (including)2.19.2 (including)

References