CVE-2006-0914

Bugzilla 2.16.10, 2.17 through 2.18.4, and 2.20 does not properly handle certain characters in the mostfreqthreshold parameter in duplicates.cgi, which allows remote attackers to trigger a SQL error.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:bugzilla:2.16.10:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.17:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.17.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.17.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.17.6:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.17.7:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.18:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.18:rc1:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.18:rc2:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.18.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.18.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.18.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.18.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.20:rc1:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.20:rc2:*:*:*:*:*:*

History

21 Nov 2024, 00:07

Type Values Removed Values Added
References () http://www.securityfocus.com/archive/1/425584/100/0/threaded - () http://www.securityfocus.com/archive/1/425584/100/0/threaded -
References () http://www.vupen.com/english/advisories/2006/0692 - () http://www.vupen.com/english/advisories/2006/0692 -
References () https://bugzilla.mozilla.org/show_bug.cgi?id=312498 - Exploit, Patch, Vendor Advisory () https://bugzilla.mozilla.org/show_bug.cgi?id=312498 - Exploit, Patch, Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/42802 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/42802 -

Information

Published : 2006-02-28 11:02

Updated : 2024-11-21 00:07


NVD link : CVE-2006-0914

Mitre link : CVE-2006-0914

CVE.ORG link : CVE-2006-0914


JSON object : View

Products Affected

mozilla

  • bugzilla
CWE
CWE-20

Improper Input Validation