TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2014-8630

N/A

Beschreibung

Bugzilla before 4.0.16, 4.1.x and 4.2.x before 4.2.12, 4.3.x and 4.4.x before 4.4.7, and 5.x before 5.0rc1 allows remote authenticated users to execute arbitrary commands by leveraging the editcomponents privilege and triggering crafted input to a two-argument Perl open call, as demonstrated by shell metacharacters in a product name.

CVE Details

CVSS v3.1 BewertungN/A
Veroffentlicht2/1/2015
Zuletzt geandert4/12/2025
Quellenvd
Honeypot-Sichtungen0

Betroffene Produkte

fedoraproject:fedoramozilla:bugzilla

Schwachen (CWE)

CWE-77

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.