Executive Summary

Informations
Name CVE-2006-5455 First vendor Publication 2006-10-23
Vendor Cve Last vendor Modification 2018-10-17

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:H/Au:N/C:N/I:P/A:N)
Cvss Base Score 2.6 Attack Range Network
Cvss Impact Score 2.9 Attack Complexity High
Cvss Expoit Score 4.9 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Cross-site request forgery (CSRF) vulnerability in editversions.cgi in Bugzilla before 2.22.1 and 2.23.x before 2.23.3 allows user-assisted remote attackers to create, modify, or delete arbitrary bug reports via a crafted URL.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5455

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 77

OpenVAS Exploits

Date Description
2008-09-24 Name : Gentoo Security Advisory GLSA 200611-04 (bugzilla)
File : nvt/glsa_200611_04.nasl
2008-09-04 Name : FreeBSD Ports: bugzilla, ja-bugzilla
File : nvt/freebsd_bugzilla2.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
29548 Bugzilla Crafted URL User-complicit Arbitrary Command Execution

Bugzilla contains a flaw related to the sanitization of input in multiple instances. A specially crafted URL could lead to user-complicit arbitrary command execution. This may allow an attacker to conduct cross-site scripting, script insertion, request forgery attacks as well as disclose potentially sensitive information.

Nessus® Vulnerability Scanner

Date Description
2006-11-20 Name : The remote FreeBSD host is missing one or more security-related updates.
File : freebsd_pkg_6d68618a719911dba2ad000c6ec775d9.nasl - Type : ACT_GATHER_INFO
2006-11-20 Name : The remote Gentoo host is missing one or more security-related patches.
File : gentoo_GLSA-200611-04.nasl - Type : ACT_GATHER_INFO

Sources (Detail)

Source Url
BID http://www.securityfocus.com/bid/20538
BUGTRAQ http://www.securityfocus.com/archive/1/448777/100/100/threaded
CONFIRM http://www.bugzilla.org/security/2.18.5/
https://bugzilla.mozilla.org/show_bug.cgi?id=281181
GENTOO http://security.gentoo.org/glsa/glsa-200611-04.xml
OSVDB http://www.osvdb.org/29548
SECUNIA http://secunia.com/advisories/22409
http://secunia.com/advisories/22790
SREASON http://securityreason.com/securityalert/1760
VUPEN http://www.vupen.com/english/advisories/2006/4035
XF https://exchange.xforce.ibmcloud.com/vulnerabilities/29618

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
Date Informations
2021-05-05 01:02:55
  • Multiple Updates
2021-05-04 12:04:45
  • Multiple Updates
2021-04-22 01:05:22
  • Multiple Updates
2020-05-24 01:02:56
  • Multiple Updates
2020-05-23 00:18:35
  • Multiple Updates
2019-05-09 12:01:55
  • Multiple Updates
2018-10-18 00:19:45
  • Multiple Updates
2017-07-20 09:23:58
  • Multiple Updates
2016-06-28 15:59:13
  • Multiple Updates
2016-04-26 15:12:50
  • Multiple Updates
2014-02-17 10:37:39
  • Multiple Updates
2013-05-11 11:12:21
  • Multiple Updates