CVE Vulnerabilities

CVE-2006-0915

Published: Feb 28, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Bugzilla 2.16.10 does not properly handle certain characters in the (1) maxpatchsize and (2) maxattachmentsize parameters in attachment.cgi, which allows remote attackers to trigger a SQL error.

Affected Software

NameVendorStart VersionEnd Version
BugzillaMozilla2.16.10 (including)2.16.10 (including)
BugzillaUbuntudapper*
BugzillaUbuntuupstream*

References