First published: Mon Oct 23 2006(Updated: )
Cross-site request forgery (CSRF) vulnerability in editversions.cgi in Bugzilla before 2.22.1 and 2.23.x before 2.23.3 allows user-assisted remote attackers to create, modify, or delete arbitrary bug reports via a crafted URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Bugzilla | <=2.22.1 | |
Mozilla Bugzilla | =2.23.2 | |
Mozilla Bugzilla | =2.23.1 | |
Mozilla Bugzilla | =2.23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5455 has a medium severity rating, allowing attackers to exploit it if a user is tricked into clicking a malicious link.
To fix CVE-2006-5455, upgrade Bugzilla to version 2.22.1 or 2.23.3 or later.
CVE-2006-5455 affects users of Bugzilla versions prior to 2.22.1 and 2.23.x prior to 2.23.3.
CVE-2006-5455 is a cross-site request forgery (CSRF) vulnerability.
Attackers exploiting CVE-2006-5455 can create, modify, or delete arbitrary bug reports.