CVE-2011-0046

Multiple cross-site request forgery (CSRF) vulnerabilities in Bugzilla before 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and 4.0.x before 4.0rc2 allow remote attackers to hijack the authentication of arbitrary users for requests related to (1) adding a saved search in buglist.cgi, (2) voting in votes.cgi, (3) sanity checking in sanitycheck.cgi, (4) creating or editing a chart in chart.cgi, (5) column changing in colchange.cgi, and (6) adding, deleting, or approving a quip in quips.cgi.
References
Link Resource
http://lists.fedoraproject.org/pipermail/package-announce/2011-February/053665.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-February/053678.html
http://osvdb.org/70705
http://osvdb.org/70706
http://osvdb.org/70707
http://osvdb.org/70708
http://osvdb.org/70709
http://osvdb.org/70710
http://secunia.com/advisories/43033 Vendor Advisory
http://secunia.com/advisories/43165
http://www.bugzilla.org/security/3.2.9/ Vendor Advisory
http://www.debian.org/security/2011/dsa-2322
http://www.securityfocus.com/bid/45982
http://www.vupen.com/english/advisories/2011/0207 Vendor Advisory
http://www.vupen.com/english/advisories/2011/0271
https://bugzilla.mozilla.org/show_bug.cgi?id=621090 Patch
https://bugzilla.mozilla.org/show_bug.cgi?id=621105 Patch
https://bugzilla.mozilla.org/show_bug.cgi?id=621107 Patch
https://bugzilla.mozilla.org/show_bug.cgi?id=621108 Patch
https://bugzilla.mozilla.org/show_bug.cgi?id=621109 Patch
https://bugzilla.mozilla.org/show_bug.cgi?id=621110 Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/65003
http://lists.fedoraproject.org/pipermail/package-announce/2011-February/053665.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-February/053678.html
http://osvdb.org/70705
http://osvdb.org/70706
http://osvdb.org/70707
http://osvdb.org/70708
http://osvdb.org/70709
http://osvdb.org/70710
http://secunia.com/advisories/43033 Vendor Advisory
http://secunia.com/advisories/43165
http://www.bugzilla.org/security/3.2.9/ Vendor Advisory
http://www.debian.org/security/2011/dsa-2322
http://www.securityfocus.com/bid/45982
http://www.vupen.com/english/advisories/2011/0207 Vendor Advisory
http://www.vupen.com/english/advisories/2011/0271
https://bugzilla.mozilla.org/show_bug.cgi?id=621090 Patch
https://bugzilla.mozilla.org/show_bug.cgi?id=621105 Patch
https://bugzilla.mozilla.org/show_bug.cgi?id=621107 Patch
https://bugzilla.mozilla.org/show_bug.cgi?id=621108 Patch
https://bugzilla.mozilla.org/show_bug.cgi?id=621109 Patch
https://bugzilla.mozilla.org/show_bug.cgi?id=621110 Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/65003
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:bugzilla:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.6:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.8:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.9:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.10:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.12:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.14:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.14.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.14.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.14.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.14.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.14.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.16:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.16:rc1:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.16:rc2:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.16.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.16.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.16.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.16.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.16.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.16.6:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.16.7:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.16.8:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.16.9:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.16.10:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.16.11:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.16_rc2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.17:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.17.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.17.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.17.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.17.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.17.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.17.6:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.17.7:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.18:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.18:rc1:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.18:rc2:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.18:rc3:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.18.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.18.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.18.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.18.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.18.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.18.6:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.18.6\+:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.18.7:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.18.8:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.18.9:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.19:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.19.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.19.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.19.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.20:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.20:rc1:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.20:rc2:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.20.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.20.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.20.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.20.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.20.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.20.6:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.20.7:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.21:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.21.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.21.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.22:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.22:rc1:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.22.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.22.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.22.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.22.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.22.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.22.6:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.22.7:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.23:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.23.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.23.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.23.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.23.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:3.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:3.2:rc1:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:3.2:rc2:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:3.2.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:3.2.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:3.2.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:3.2.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:3.2.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:3.2.6:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:3.2.7:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:3.2.8:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:3.4.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:3.4.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:3.4.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:3.4.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:3.4.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:3.4.6:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:3.4.7:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:3.4.8:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:3.4.9:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:3.6.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:3.6.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:3.6.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:3.6.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:4.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:4.0:rc1:*:*:*:*:*:*

History

21 Nov 2024, 01:23

Type Values Removed Values Added
References () http://lists.fedoraproject.org/pipermail/package-announce/2011-February/053665.html - () http://lists.fedoraproject.org/pipermail/package-announce/2011-February/053665.html -
References () http://lists.fedoraproject.org/pipermail/package-announce/2011-February/053678.html - () http://lists.fedoraproject.org/pipermail/package-announce/2011-February/053678.html -
References () http://osvdb.org/70705 - () http://osvdb.org/70705 -
References () http://osvdb.org/70706 - () http://osvdb.org/70706 -
References () http://osvdb.org/70707 - () http://osvdb.org/70707 -
References () http://osvdb.org/70708 - () http://osvdb.org/70708 -
References () http://osvdb.org/70709 - () http://osvdb.org/70709 -
References () http://osvdb.org/70710 - () http://osvdb.org/70710 -
References () http://secunia.com/advisories/43033 - Vendor Advisory () http://secunia.com/advisories/43033 - Vendor Advisory
References () http://secunia.com/advisories/43165 - () http://secunia.com/advisories/43165 -
References () http://www.bugzilla.org/security/3.2.9/ - Vendor Advisory () http://www.bugzilla.org/security/3.2.9/ - Vendor Advisory
References () http://www.debian.org/security/2011/dsa-2322 - () http://www.debian.org/security/2011/dsa-2322 -
References () http://www.securityfocus.com/bid/45982 - () http://www.securityfocus.com/bid/45982 -
References () http://www.vupen.com/english/advisories/2011/0207 - Vendor Advisory () http://www.vupen.com/english/advisories/2011/0207 - Vendor Advisory
References () http://www.vupen.com/english/advisories/2011/0271 - () http://www.vupen.com/english/advisories/2011/0271 -
References () https://bugzilla.mozilla.org/show_bug.cgi?id=621090 - Patch () https://bugzilla.mozilla.org/show_bug.cgi?id=621090 - Patch
References () https://bugzilla.mozilla.org/show_bug.cgi?id=621105 - Patch () https://bugzilla.mozilla.org/show_bug.cgi?id=621105 - Patch
References () https://bugzilla.mozilla.org/show_bug.cgi?id=621107 - Patch () https://bugzilla.mozilla.org/show_bug.cgi?id=621107 - Patch
References () https://bugzilla.mozilla.org/show_bug.cgi?id=621108 - Patch () https://bugzilla.mozilla.org/show_bug.cgi?id=621108 - Patch
References () https://bugzilla.mozilla.org/show_bug.cgi?id=621109 - Patch () https://bugzilla.mozilla.org/show_bug.cgi?id=621109 - Patch
References () https://bugzilla.mozilla.org/show_bug.cgi?id=621110 - Patch () https://bugzilla.mozilla.org/show_bug.cgi?id=621110 - Patch
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/65003 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/65003 -

Information

Published : 2011-01-28 16:00

Updated : 2024-11-21 01:23


NVD link : CVE-2011-0046

Mitre link : CVE-2011-0046

CVE.ORG link : CVE-2011-0046


JSON object : View

Products Affected

mozilla

  • bugzilla
CWE
CWE-352

Cross-Site Request Forgery (CSRF)