Executive Summary
| Informations | |||
|---|---|---|---|
| Name | CVE-2009-3165 | First vendor Publication | 2009-09-15 |
| Vendor | Cve | Last vendor Modification | 2009-09-16 |
Security-Database Scoring CVSS v2
| Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P) | |||
|---|---|---|---|
| Cvss Base Score | 7.5 | Attack Range | Network |
| Cvss Impact Score | 6.4 | Attack Complexity | Low |
| Cvss Expoit Score | 10 | Authentification | None Required |
| Calculate full CVSS 2.0 Vectors scores | |||
Detail
SQL injection vulnerability in the Bug.create WebService function in Bugzilla 2.23.4 through 3.0.8, 3.1.1 through 3.2.4, and 3.3.1 through 3.4.1 allows remote attackers to execute arbitrary SQL commands via unspecified parameters. |
Original Source
| Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3165 |
CWE : Common Weakness Enumeration
| id | Name |
|---|---|
| CWE-89 | Improper Sanitization of Special Elements used in an SQL Command ('SQL Injection') |
CPE : Common Platform Enumeration
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 58088 | Bugzilla Bug.create WebService Function Unspecified SQL Injection |
Internal Sources (Detail)
| Source | Url |
|---|---|
| BID | http://www.securityfocus.com/bid/36373 |
| CONFIRM | http://www.bugzilla.org/security/3.0.8/ https://bugzilla.mozilla.org/show_bug.cgi?id=515191 |
| SECUNIA | http://secunia.com/advisories/36718 |
Alert History
| Date | Informations |
|---|---|
| 2013-05-10 23:57:16 |
|

CVE-2009-3165
(High)





