|
Bugzilla contains a flaw that may allow a remote attacker to inject arbitrary SQL queries. This flaw exists because the application does not validate user-supplied input upon submission to the 'collectstats.pl' script and may allow a remote attacker with 'editproducts' privileges to inject or manipulate SQL queries.
|