Executive Summary

Informations
NameCVE-2009-3165First vendor Publication2009-09-15
VendorCveLast vendor Modification2009-09-16

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P)
Cvss Base Score7.5Attack RangeNetwork
Cvss Impact Score6.4Attack ComplexityLow
Cvss Expoit Score10AuthentificationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

SQL injection vulnerability in the Bug.create WebService function in Bugzilla 2.23.4 through 3.0.8, 3.1.1 through 3.2.4, and 3.3.1 through 3.4.1 allows remote attackers to execute arbitrary SQL commands via unspecified parameters.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3165

CWE : Common Weakness Enumeration

idName
CWE-89Improper Sanitization of Special Elements used in an SQL Command ('SQL Injection')

CPE : Common Platform Enumeration

TypeDescriptionCount
Application29

Open Source Vulnerability Database (OSVDB)

idDescription
58088Bugzilla Bug.create WebService Function Unspecified SQL Injection

Internal Sources (Detail)

SourceUrl
BIDhttp://www.securityfocus.com/bid/36373
CONFIRMhttp://www.bugzilla.org/security/3.0.8/
https://bugzilla.mozilla.org/show_bug.cgi?id=515191
SECUNIAhttp://secunia.com/advisories/36718

Alert History

If you want to see full details history, please login or register.
0
DateInformations
2013-05-10 23:57:16
  • Multiple Updates