Bugzilla 2.10 allows remote attackers to access sensitive information, including the database username and password, via an HTTP request for the globals.pl file, which is normally returned by the web server without being executed.
2001-06-27T04:00:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mozilla | bugzilla | 2.4 | Yes |
Application | mozilla | bugzilla | 2.6 | Yes |
Application | mozilla | bugzilla | 2.8 | Yes |
Application | mozilla | bugzilla | 2.10 | Yes |