Record summary

CVE-2008-4437 has a selected CVSS score of 7.1; EIP currently links 1 catalogued exploit.

Description

Directory traversal vulnerability in importxml.pl in Bugzilla before 2.22.5, and 3.x before 3.0.5, when --attach_path is enabled, allows remote attackers to read arbitrary files via an XML file with a .. (dot dot) in the data element.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBBugzilla 3.1.4 - '--attach_path' Directory TraversalExploitDB exploitby ilja van sprundelNot analyzed1 file
ExploitDB

PoC details

References

11