2024-11-22 07:15:30 +00:00

198 lines
5.7 KiB
JSON

{
"id": "CVE-2007-5038",
"sourceIdentifier": "cve@mitre.org",
"published": "2007-09-24T00:17:00.000",
"lastModified": "2024-11-21T00:36:59.897",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "The offer_account_by_email function in User.pm in the WebService for Bugzilla before 3.0.2, and 3.1.x before 3.1.2, does not check the value of the createemailregexp parameter, which allows remote attackers to bypass intended restrictions on account creation."
},
{
"lang": "es",
"value": "La funci\u00f3n offer_account_by_email en User.pm en el WebService para Bugzilla before 3.0.2, y 3.1.x anterior a 3.1.2, no valida el valor del par\u00e1metro createemailregexp, el cual permite a atacantes remotos evitar las restricciones previstas sobre la creaci\u00f3n de una cuenta."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"baseScore": 7.5,
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL"
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mozilla:bugzilla:3.0.0:*:*:*:*:*:*:*",
"matchCriteriaId": "45C36666-518F-4956-816A-940930425955"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mozilla:bugzilla:3.0.1:*:*:*:*:*:*:*",
"matchCriteriaId": "FF2DF96F-E45E-45AF-85E5-E939F923EC1B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mozilla:bugzilla:3.1.0:*:*:*:*:*:*:*",
"matchCriteriaId": "154EA18F-534C-4095-837D-BB9865D25F23"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mozilla:bugzilla:3.1.1:*:*:*:*:*:*:*",
"matchCriteriaId": "585F05F2-B294-4218-9209-C487B4D2994B"
}
]
}
]
}
],
"references": [
{
"url": "http://fedoranews.org/updates/FEDORA-2007-229.shtml",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/26848",
"source": "cve@mitre.org",
"tags": [
"Patch",
"Vendor Advisory"
]
},
{
"url": "http://secunia.com/advisories/26969",
"source": "cve@mitre.org"
},
{
"url": "http://www.bugzilla.org/security/3.0.1/",
"source": "cve@mitre.org",
"tags": [
"Patch"
]
},
{
"url": "http://www.securityfocus.com/archive/1/480077/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/25725",
"source": "cve@mitre.org"
},
{
"url": "http://www.securitytracker.com/id?1018719",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2007/3200",
"source": "cve@mitre.org"
},
{
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=395632",
"source": "cve@mitre.org",
"tags": [
"Exploit"
]
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=299981",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/36692",
"source": "cve@mitre.org"
},
{
"url": "http://fedoranews.org/updates/FEDORA-2007-229.shtml",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/26848",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Patch",
"Vendor Advisory"
]
},
{
"url": "http://secunia.com/advisories/26969",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.bugzilla.org/security/3.0.1/",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Patch"
]
},
{
"url": "http://www.securityfocus.com/archive/1/480077/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/25725",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id?1018719",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2007/3200",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=395632",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Exploit"
]
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=299981",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/36692",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}