Lucene search

K
cveMitreCVE-2005-3138
HistoryOct 05, 2005 - 9:02 p.m.

CVE-2005-3138

2005-10-0521:02:00
mitre
web.nvd.nist.gov
28
bugzilla
cve-2005-3138
security vulnerability
information disclosure
remote attack

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.2

Confidence

Low

EPSS

0.016

Percentile

87.2%

Bugzilla 2.18rc1 through 2.18.3, 2.19 through 2.20rc2, and 2.21 allows remote attackers to obtain sensitive information such as the list of installed products via the config.cgi file, which is accessible even when the requirelogin parameter is set.

Affected configurations

Nvd
Node
mozillabugzillaMatch2.18rc1
OR
mozillabugzillaMatch2.18rc2
OR
mozillabugzillaMatch2.18rc3
OR
mozillabugzillaMatch2.18.1
OR
mozillabugzillaMatch2.18.2
OR
mozillabugzillaMatch2.18.3
OR
mozillabugzillaMatch2.19
OR
mozillabugzillaMatch2.19.1
OR
mozillabugzillaMatch2.19.2
OR
mozillabugzillaMatch2.19.3
OR
mozillabugzillaMatch2.20rc1
OR
mozillabugzillaMatch2.20rc2
OR
mozillabugzillaMatch2.21
VendorProductVersionCPE
mozillabugzilla2.18cpe:2.3:a:mozilla:bugzilla:2.18:rc1:*:*:*:*:*:*
mozillabugzilla2.18cpe:2.3:a:mozilla:bugzilla:2.18:rc2:*:*:*:*:*:*
mozillabugzilla2.18cpe:2.3:a:mozilla:bugzilla:2.18:rc3:*:*:*:*:*:*
mozillabugzilla2.18.1cpe:2.3:a:mozilla:bugzilla:2.18.1:*:*:*:*:*:*:*
mozillabugzilla2.18.2cpe:2.3:a:mozilla:bugzilla:2.18.2:*:*:*:*:*:*:*
mozillabugzilla2.18.3cpe:2.3:a:mozilla:bugzilla:2.18.3:*:*:*:*:*:*:*
mozillabugzilla2.19cpe:2.3:a:mozilla:bugzilla:2.19:*:*:*:*:*:*:*
mozillabugzilla2.19.1cpe:2.3:a:mozilla:bugzilla:2.19.1:*:*:*:*:*:*:*
mozillabugzilla2.19.2cpe:2.3:a:mozilla:bugzilla:2.19.2:*:*:*:*:*:*:*
mozillabugzilla2.19.3cpe:2.3:a:mozilla:bugzilla:2.19.3:*:*:*:*:*:*:*
Rows per page:
1-10 of 131

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.2

Confidence

Low

EPSS

0.016

Percentile

87.2%

Related for CVE-2005-3138