CVE-2007-5038
Last modified
CVE-2007-5038 is a vulnerability of currently unknown severity. The offer_account_by_email function in User.pm in the WebService for Bugzilla before 3.0.2, and 3.1.x before 3.1.2, does not check the value of the createemailregexp parameter, which allows remote attackers to bypass intended restrictions on account creation.. EPSS estimates a 1.96% chance of exploitation in the next 30 days.
Description
The offer_account_by_email function in User.pm in the WebService for Bugzilla before 3.0.2, and 3.1.x before 3.1.2, does not check the value of the createemailregexp parameter, which allows remote attackers to bypass intended restrictions on account creation.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Bugzilla | 3.0.0 |
| Mozilla | Bugzilla | 3.0.1 |
| Mozilla | Bugzilla | 3.1.0 |
| Mozilla | Bugzilla | 3.1.1 |
References
- http://secunia.com/advisories/26848Patch, Vendor Advisory
- http://secunia.com/advisories/26848Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-5038?
How severe is CVE-2007-5038?
How do I fix CVE-2007-5038?
Are you affected by CVE-2007-5038?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
