CVE-2007-0792
 
Severity Score
7.5
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The mod_perl initialization script in Bugzilla 2.23.3 does not set the Bugzilla Apache configuration to allow .htaccess permissions to override file permissions, which allows remote attackers to obtain the database username and password via a direct request for the localconfig file.
La secuencia de comandos de inicialización de mod_perl en Bugzilla 2.23.3 no establece la configuración de Bugzilla Apache para permitir sobrescribir los permisos del fichero .htaccess, lo cual permite a atacantes remotos obtener el nombre de usuario y la contraseña mediante una petición directa al fichero localconfig.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2007-02-06 CVE Reserved
- 2007-02-06 CVE Published
- 2024-04-03 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://osvdb.org/35862 | Vdb Entry | |
http://securityreason.com/securityalert/2222 | Third Party Advisory | |
http://securitytracker.com/id?1017585 | Vdb Entry | |
http://www.securityfocus.com/archive/1/459025/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/22380 | Vdb Entry | |
http://www.vupen.com/english/advisories/2007/0477 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/32252 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.bugzilla.org/security/2.20.3 | 2018-10-16 |