OSVDB ID: 7782

Title: Bugzilla Image URL Password Disclosure

Info

Disclosure

Feb 24, 2004

Discovery

Unknown

Dates

Exploit

Feb 24, 2004

Solution

Unknown

Description

Bugzilla contains a flaw that may lead to an unauthorized password exposure. When a user is prompted to authenticate when attempting to view a chart, the user's login ID and password are stored in the Web server logs, resulting in a loss of confidentiality.

Classification

Location: Remote / Network Access
Attack Type: Information Disclosure
Impact: Loss of Confidentiality
Exploit: Exploit Public

Solution

Upgrade to version 2.16.6, 2.18rc1 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Mozilla Organization

Bugzilla

2.17.7
2.17.6
2.17.5

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/7782