First published: Tue Feb 28 2006(Updated: )
Bugzilla 2.16.10 does not properly handle certain characters in the (1) maxpatchsize and (2) maxattachmentsize parameters in attachment.cgi, which allows remote attackers to trigger a SQL error.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Bugzilla | =2.16.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0915 has a medium severity rating due to the potential for remote attackers to trigger SQL errors.
To fix CVE-2006-0915, it is recommended to upgrade Bugzilla to a version that addresses this vulnerability.
CVE-2006-0915 affects Bugzilla version 2.16.10.
CVE-2006-0915 can lead to SQL errors, potentially resulting in application instability or denial of service.
Yes, CVE-2006-0915 is a web application vulnerability affecting how Bugzilla handles certain parameters.