Directory traversal vulnerability in importxml.pl in Bugzilla before 2.22.5, and 3.x before 3.0.5, when --attach_path is enabled, allows remote attackers to read arbitrary files via an XML file with a .. (dot dot) in the data element.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2008-10-03 22:22
Updated : 2025-04-09 00:30
NVD link : CVE-2008-4437
Mitre link : CVE-2008-4437
CVE.ORG link : CVE-2008-4437
JSON object : View
Products Affected
mozilla
- bugzilla
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')