Lucene search

K
ubuntucveUbuntu.comUB:CVE-2008-6098
HistoryFeb 09, 2009 - 12:00 a.m.

CVE-2008-6098

2009-02-0900:00:00
ubuntu.com
ubuntu.com
20

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:N/A:P

EPSS

0.004

Percentile

73.5%

Bugzilla 3.2 before 3.2 RC2, 3.0 before 3.0.6, 2.22 before 2.22.6, 2.20
before 2.20.7, and other versions after 2.17.4 allows remote authenticated
users to bypass moderation to approve and disapprove quips via a direct
request to quips.cgi with the action parameter set to “approve.”

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:N/A:P

EPSS

0.004

Percentile

73.5%