CVE-2006-0915

Bugzilla 2.16.10 - SQL Injection via Maxpatchsize and Maxattachmentsize Parameters

Title source: llm
STIX 2.1

Description

Bugzilla 2.16.10 does not properly handle certain characters in the (1) maxpatchsize and (2) maxattachmentsize parameters in attachment.cgi, which allows remote attackers to trigger a SQL error.

References (2)

Core 2
Core References
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/0692
Issue Tracking x_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=313441

Scores

EPSS 0.0116
EPSS Percentile 63.7%

Details

Status published
Products (1)
mozilla/bugzilla 2.16.10
Published Feb 28, 2006
Tracked Since Feb 18, 2026