CVE-2006-5455: CSRF
Published Oct 23, 2006
·Updated
Cross-site request forgery (CSRF) vulnerability in editversions.cgi in Bugzilla before 2.22.1 and 2.23.x before 2.23.3 allows user-assisted remote attackers to create, modify, or delete arbitrary bug reports via a crafted URL.
Affected Software
4 affected components
Bugzilla<=2.22.1
Bugzilla=2.23.2
Bugzilla=2.23.1
Bugzilla=2.23
Remediation
Patch Available
Event History
Oct 23, 2006
CVE Published
05:07 PM
Data Sourced
via NVD·05:07 PM
RemedyDescriptionSeverityAffected Software
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-5455?
CVE-2006-5455 has a medium severity rating, allowing attackers to exploit it if a user is tricked into clicking a malicious link.
2
How do I fix CVE-2006-5455?
To fix CVE-2006-5455, upgrade Bugzilla to version 2.22.1 or 2.23.3 or later.
3
Who is affected by CVE-2006-5455?
CVE-2006-5455 affects users of Bugzilla versions prior to 2.22.1 and 2.23.x prior to 2.23.3.
4
What type of vulnerability is CVE-2006-5455?
CVE-2006-5455 is a cross-site request forgery (CSRF) vulnerability.
5
What can attackers do with CVE-2006-5455?
Attackers exploiting CVE-2006-5455 can create, modify, or delete arbitrary bug reports.