Record summary

CVE-2001-0329 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.

Description

Bugzilla 2.10 allows remote attackers to execute arbitrary commands via shell metacharacters in a username that is then processed by (1) the Bugzilla_login cookie in post_bug.cgi, or (2) the who parameter in process_bug.cgi.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBMozilla Bugzilla 2.4/2.6/2.8/2.10 - Arbitrary Command ExecutionExploitDB exploitby Frank van Vliet karinNot analyzed1 file
ExploitDB

PoC details

References

4