CVE Vulnerabilities

CVE-2006-0913

Published: Feb 28, 2006 | Modified: Oct 18, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.5 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

SQL injection vulnerability in whineatnews.pl in Bugzilla 2.17 through 2.18.4 and 2.20 allows remote authenticated users with administrative privileges to execute arbitrary SQL commands via the whinedays parameter, as accessible from editparams.cgi.

Affected Software

Name Vendor Start Version End Version
Bugzilla Mozilla 2.17.1 (including) 2.17.1 (including)
Bugzilla Mozilla 2.17.3 (including) 2.17.3 (including)
Bugzilla Mozilla 2.17.4 (including) 2.17.4 (including)
Bugzilla Mozilla 2.17.5 (including) 2.17.5 (including)
Bugzilla Mozilla 2.17.6 (including) 2.17.6 (including)
Bugzilla Mozilla 2.17.7 (including) 2.17.7 (including)
Bugzilla Mozilla 2.18-rc1 (including) 2.18-rc1 (including)
Bugzilla Mozilla 2.18-rc2 (including) 2.18-rc2 (including)
Bugzilla Mozilla 2.18-rc3 (including) 2.18-rc3 (including)
Bugzilla Mozilla 2.18.1 (including) 2.18.1 (including)
Bugzilla Mozilla 2.18.2 (including) 2.18.2 (including)
Bugzilla Mozilla 2.18.3 (including) 2.18.3 (including)
Bugzilla Mozilla 2.18.4 (including) 2.18.4 (including)
Bugzilla Mozilla 2.19 (including) 2.19 (including)
Bugzilla Mozilla 2.19.1 (including) 2.19.1 (including)
Bugzilla Mozilla 2.19.2 (including) 2.19.2 (including)
Bugzilla Mozilla 2.19.3 (including) 2.19.3 (including)
Bugzilla Mozilla 2.20 (including) 2.20 (including)
Bugzilla Mozilla 2.20-rc1 (including) 2.20-rc1 (including)
Bugzilla Mozilla 2.20-rc2 (including) 2.20-rc2 (including)
Bugzilla Mozilla 2.21 (including) 2.21 (including)
Bugzilla Mozilla 2.21.1 (including) 2.21.1 (including)
Bugzilla Ubuntu dapper *
Bugzilla Ubuntu upstream *

References