cvelist/2009/3xxx/CVE-2009-3989.json
2019-03-17 23:25:21 +00:00

92 lines
3.1 KiB
JSON

{
"CVE_data_meta": {
"ASSIGNER": "cve@mitre.org",
"ID": "CVE-2009-3989",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "https://bugzilla.mozilla.org/show_bug.cgi?id=314871",
"refsource": "CONFIRM",
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=314871"
},
{
"name": "bugzilla-files-info-disclosure(56003)",
"refsource": "XF",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/56003"
},
{
"name": "https://bugzilla.mozilla.org/show_bug.cgi?id=434801",
"refsource": "CONFIRM",
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=434801"
},
{
"name": "ADV-2010-0261",
"refsource": "VUPEN",
"url": "http://www.vupen.com/english/advisories/2010/0261"
},
{
"name": "38025",
"refsource": "BID",
"url": "http://www.securityfocus.com/bid/38025"
},
{
"name": "20100201 Security Advisory for Bugzilla 3.0.10, 3.2.5, 3.4.4, and 3.5.2",
"refsource": "BUGTRAQ",
"url": "http://www.securityfocus.com/archive/1/509282/100/0/threaded"
},
{
"name": "38443",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/38443"
}
]
}
}