Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
CGI.pl in Bugzilla before 2.14.1, when using LDAP, allows remote attackers to obtain an anonymous bind to the LDAP server via a request that does not include a password, which causes a null password to be sent to the LDAP server.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
BugZilla LDAP认证绕过漏洞
Vulnerability Description
Bugzilla 2.14.1之前版本中CGI.pl存在漏洞。当使用LDAP时,远程攻击者借助不包含密码的请求匿名绑定到LDAP服务器上,该漏洞导致空密码发送给LDAP服务器。
CVSS Information
N/A
Vulnerability Type
N/A