Description
|
|
Multiple vulnerabilities have been identified in Bugzilla, which could be exploited by attackers to disclose or manipulate certain information.
The first issue is caused by an input validation error in the Bug.search WebService function, which could be exploited to conduct SQL injection attacks.
The second vulnerability is caused by an input validation error in the Bug.create WebService function, which could be exploited to conduct SQL injection attacks.
The third issue is caused by an error when users reset their passwords and then log in immediately afterward, which could cause passwords to appear in the URL of their browsers and in the Bugzilla webserver's logs and in the Referer header.
|