Lucene search

K
cvelistMitreCVELIST:CVE-2012-4747
HistorySep 04, 2012 - 10:00 a.m.

CVE-2012-4747

2012-09-0410:00:00
mitre
www.cve.org
6
bugzilla
sensitive information
access control
remote attackers
web root
template files
custom extension files
documentation files

AI Score

6.2

Confidence

Low

EPSS

0.003

Percentile

65.7%

Bugzilla 2.x and 3.x through 3.6.11, 3.7.x and 4.0.x before 4.0.8, 4.1.x and 4.2.x before 4.2.3, and 4.3.x before 4.3.3 stores potentially sensitive information under the web root with insufficient access control, which allows remote attackers to read (1) template (aka .tmpl) files, (2) other custom extension files under extensions/, or (3) custom documentation files under docs/ via a direct request.

AI Score

6.2

Confidence

Low

EPSS

0.003

Percentile

65.7%

Related for CVELIST:CVE-2012-4747