Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
email_in.pl in Bugzilla 2.23.4, 3.0.x before 3.0.4, and 3.1.x before 3.1.4 allows remote authenticated users to more easily spoof the changer of a bug via a @reporter command in the body of an e-mail message, which overrides the e-mail address as normally obtained from the From e-mail header. NOTE: since From headers are easily spoofed, this only crosses privilege boundaries in environments that provide additional verification of e-mail addresses.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mozilla Bugzilla Bugzilla绕过安全限制和跨站脚本漏洞
Vulnerability Description
Bugzilla是很多软件项目都在使用的基于Web的BUG跟踪系统。在2.23.4,3.0.3之前的版本和3.1.3之前的版本.远程攻击者可在利用和欺骗中E-MAIL信息中的@reporter命令;可以忽略E-MAIL地址从E-MAIL报头.
CVSS Information
N/A
Vulnerability Type
N/A