Page 8 of 71 results (0.011 seconds)

CVSS: 9.8EPSS: 4%CPEs: 4EXPL: 1

24 May 2001 — Bugzilla 2.10 allows remote attackers to execute arbitrary commands via shell metacharacters in a username that is then processed by (1) the Bugzilla_login cookie in post_bug.cgi, or (2) the who parameter in process_bug.cgi. • https://www.exploit-db.com/exploits/19909 •