Lucene search

K
nvd[email protected]NVD:CVE-2012-0453
HistoryFeb 25, 2012 - 4:21 a.m.

CVE-2012-0453

2012-02-2504:21:42
CWE-352
web.nvd.nist.gov
7

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

AI Score

7

Confidence

Low

EPSS

0.002

Percentile

52.5%

Cross-site request forgery (CSRF) vulnerability in xmlrpc.cgi in Bugzilla 4.0.2 through 4.0.4 and 4.1.1 through 4.2rc2, when mod_perl is used, allows remote attackers to hijack the authentication of arbitrary users for requests that modify the product’s installation via the XML-RPC API.

Affected configurations

Nvd
Node
mozillabugzillaMatch4.0.2
OR
mozillabugzillaMatch4.0.3
OR
mozillabugzillaMatch4.0.4
Node
mozillabugzillaMatch4.1.1
OR
mozillabugzillaMatch4.1.2
OR
mozillabugzillaMatch4.1.3
OR
mozillabugzillaMatch4.2rc1
OR
mozillabugzillaMatch4.2rc2
VendorProductVersionCPE
mozillabugzilla4.0.2cpe:2.3:a:mozilla:bugzilla:4.0.2:*:*:*:*:*:*:*
mozillabugzilla4.0.3cpe:2.3:a:mozilla:bugzilla:4.0.3:*:*:*:*:*:*:*
mozillabugzilla4.0.4cpe:2.3:a:mozilla:bugzilla:4.0.4:*:*:*:*:*:*:*
mozillabugzilla4.1.1cpe:2.3:a:mozilla:bugzilla:4.1.1:*:*:*:*:*:*:*
mozillabugzilla4.1.2cpe:2.3:a:mozilla:bugzilla:4.1.2:*:*:*:*:*:*:*
mozillabugzilla4.1.3cpe:2.3:a:mozilla:bugzilla:4.1.3:*:*:*:*:*:*:*
mozillabugzilla4.2cpe:2.3:a:mozilla:bugzilla:4.2:rc1:*:*:*:*:*:*
mozillabugzilla4.2cpe:2.3:a:mozilla:bugzilla:4.2:rc2:*:*:*:*:*:*

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

AI Score

7

Confidence

Low

EPSS

0.002

Percentile

52.5%