CVE-2005-1564

Bugzilla 2.10-2.18, 2.19.1-2.19.2 - Authenticated Bypass of Product Entry Restrictions via URL Manipulation

Title source: llm
STIX 2.1

Description

post_bug.cgi in Bugzilla 2.10 through 2.18, 2.19.1, and 2.19.2 allows remote authenticated users to "enter bugs into products that are closed for bug entry" by modifying the URL to specify the name of the product.

References (6)

Core 6
Core References
Exploit, Patch, Vendor Advisory x_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=287109
Patch, Vendor Advisory vdb-entry x_refsource_osvdb
http://www.osvdb.org/16426
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/42797
Exploit, Patch, Vendor Advisory x_refsource_confirm
http://www.bugzilla.org/security/2.16.8/
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=111592031902962&w=2
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/15338

Scores

EPSS 0.0156
EPSS Percentile 72.6%

Details

Status published
Products (24)
mozilla/bugzilla 2.10
mozilla/bugzilla 2.12
mozilla/bugzilla 2.14
mozilla/bugzilla 2.14.1
mozilla/bugzilla 2.14.2
mozilla/bugzilla 2.14.3
mozilla/bugzilla 2.14.4
mozilla/bugzilla 2.14.5
mozilla/bugzilla 2.16
mozilla/bugzilla 2.16.1
... and 14 more
Published May 12, 2005
Tracked Since Feb 18, 2026