Cross-site request forgery (CSRF) vulnerability in editversions.cgi in Bugzilla before 2.22.1 and 2.23.x before 2.23.3 allows user-assisted remote attackers to create, modify, or delete arbitrary bug reports via a crafted URL.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Bugzilla | Mozilla | * | 2.22.1 (including) |
Bugzilla | Mozilla | 2.23 (including) | 2.23 (including) |
Bugzilla | Mozilla | 2.23.1 (including) | 2.23.1 (including) |
Bugzilla | Mozilla | 2.23.2 (including) | 2.23.2 (including) |
Bugzilla | Ubuntu | dapper | * |
Bugzilla | Ubuntu | devel | * |
Bugzilla | Ubuntu | edgy | * |
Bugzilla | Ubuntu | feisty | * |
Bugzilla | Ubuntu | gutsy | * |
Bugzilla | Ubuntu | hardy | * |
Bugzilla | Ubuntu | intrepid | * |
Bugzilla | Ubuntu | jaunty | * |
Bugzilla | Ubuntu | karmic | * |