CVE-2006-0914: Input Validation
Bugzilla 2.16.10, 2.17 through 2.18.4, and 2.20 does not properly handle certain characters in the mostfreqthreshold parameter in duplicates.cgi, which allows remote attackers to trigger a SQL error.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-0914?
CVE-2006-0914 has been classified as a moderate vulnerability due to the potential for a SQL error when specific characters are handled incorrectly.
How do I fix CVE-2006-0914?
To mitigate CVE-2006-0914, you should upgrade to a Bugzilla version that is not affected, such as any version later than 2.18.4.
What versions of Bugzilla are affected by CVE-2006-0914?
CVE-2006-0914 affects Bugzilla versions 2.16.10, 2.17 through 2.18.4, and 2.20.
What type of attack does CVE-2006-0914 facilitate?
CVE-2006-0914 allows remote attackers to trigger a SQL error by exploiting improper handling of characters.
Where can I find more information about CVE-2006-0914?
Detailed information about CVE-2006-0914, including its implications and fixes, can be found in Bugzilla's issue tracking system.