CVE-2007-5038
 
Severity Score
7.5
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The offer_account_by_email function in User.pm in the WebService for Bugzilla before 3.0.2, and 3.1.x before 3.1.2, does not check the value of the createemailregexp parameter, which allows remote attackers to bypass intended restrictions on account creation.
La función offer_account_by_email en User.pm en el WebService para Bugzilla before 3.0.2, y 3.1.x anterior a 3.1.2, no valida el valor del parámetro createemailregexp, el cual permite a atacantes remotos evitar las restricciones previstas sobre la creación de una cuenta.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2007-09-23 CVE Reserved
- 2007-09-24 CVE Published
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- 2024-11-19 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/26969 | Third Party Advisory | |
http://www.securityfocus.com/archive/1/480077/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/25725 | Vdb Entry | |
http://www.securitytracker.com/id?1018719 | Vdb Entry | |
http://www.vupen.com/english/advisories/2007/3200 | Vdb Entry | |
https://bugzilla.redhat.com/show_bug.cgi?id=299981 | X_refsource_confirm | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/36692 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://bugzilla.mozilla.org/show_bug.cgi?id=395632 | 2024-08-07 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/26848 | 2018-10-15 | |
http://www.bugzilla.org/security/3.0.1 | 2018-10-15 |
URL | Date | SRC |
---|---|---|
http://fedoranews.org/updates/FEDORA-2007-229.shtml | 2018-10-15 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mozilla Search vendor "Mozilla" | Bugzilla Search vendor "Mozilla" for product "Bugzilla" | 3.0.0 Search vendor "Mozilla" for product "Bugzilla" and version "3.0.0" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Bugzilla Search vendor "Mozilla" for product "Bugzilla" | 3.0.1 Search vendor "Mozilla" for product "Bugzilla" and version "3.0.1" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Bugzilla Search vendor "Mozilla" for product "Bugzilla" | 3.1.0 Search vendor "Mozilla" for product "Bugzilla" and version "3.1.0" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Bugzilla Search vendor "Mozilla" for product "Bugzilla" | 3.1.1 Search vendor "Mozilla" for product "Bugzilla" and version "3.1.1" | - |
Affected
|