CVE-2005-1564
Bugzilla 2.10-2.18, 2.19.1-2.19.2 - Authenticated Bypass of Product Entry Restrictions via URL Manipulation
Title source: llmDescription
post_bug.cgi in Bugzilla 2.10 through 2.18, 2.19.1, and 2.19.2 allows remote authenticated users to "enter bugs into products that are closed for bug entry" by modifying the URL to specify the name of the product.
References (6)
Core 6
Core References
Exploit, Patch, Vendor Advisory x_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=287109
Patch, Vendor Advisory vdb-entry
x_refsource_osvdb
http://www.osvdb.org/16426
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/42797
Exploit, Patch, Vendor Advisory x_refsource_confirm
http://www.bugzilla.org/security/2.16.8/
Mailing List mailing-list
x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=111592031902962&w=2
Patch, Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/15338
Scores
EPSS
0.0156
EPSS Percentile
72.6%
Details
Status
published
Products (24)
mozilla/bugzilla
2.10
mozilla/bugzilla
2.12
mozilla/bugzilla
2.14
mozilla/bugzilla
2.14.1
mozilla/bugzilla
2.14.2
mozilla/bugzilla
2.14.3
mozilla/bugzilla
2.14.4
mozilla/bugzilla
2.14.5
mozilla/bugzilla
2.16
mozilla/bugzilla
2.16.1
... and 14 more
Published
May 12, 2005
Tracked Since
Feb 18, 2026