31444Third-party advisory
http://secunia.com/advisories/31444 CVE-2008-4437
Bugzilla 3.1.4 - '--attach_path' Directory Traversal
Record summary
CVE-2008-4437 has a selected CVSS score of 7.1; EIP currently links 1 catalogued exploit.
Description
Directory traversal vulnerability in importxml.pl in Bugzilla before 2.22.5, and 3.x before 3.0.5, when --attach_path is enabled, allows remote attackers to read arbitrary files via an XML file with a .. (dot dot) in the data element.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBBugzilla 3.1.4 - '--attach_path' Directory TraversalExploitDB exploitby ilja van sprundelNot analyzed1 file
References
1134361Third-party advisory
http://secunia.com/advisories/34361 bugzilla.orgConfirmation
http://www.bugzilla.org/security/2.22.4 30661vdb entry
http://www.securityfocus.com/bid/30661 1020668vdb entry
http://www.securitytracker.com/id?1020668 ADV-2008-2344vdb entry
http://www.vupen.com/english/advisories/2008/2344 bugzilla.mozilla.org
https://bugzilla.mozilla.org/show_bug.cgi?id=437169 bugzilla-importxml-directory-traversal(44407)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/44407 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-4437 FEDORA-2009-2418Vendor advisory
https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00664.html FEDORA-2009-2417Vendor advisory
https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00687.html