Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Bugzilla 2.18rc1 through 2.18.3, 2.19 through 2.20rc2, and 2.21 allows remote attackers to obtain sensitive information such as the list of installed products via the config.cgi file, which is accessible even when the requirelogin parameter is set.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Bugzilla config.cgi 信息泄露漏洞
Vulnerability Description
Bugzilla 是一个用于软件缺陷追踪的网络应用程序。 Bugzilla 2.18rc1到2.18.3, 2.19到2.20rc2和2.21可以使远程攻击者借助即使设置了requirelogin参数也能访问的config.cgi 文件,获取敏感信息,例如所安装产品清单。
CVSS Information
N/A
Vulnerability Type
N/A