Bugzilla 2.17.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 generates different error messages depending on whether a product exists, which makes it easier for remote attackers to guess product names via unspecified use of the (1) Reports or (2) Duplicates page.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2010-08-13T19:00:00
Updated: 2024-08-07T02:46:48.196Z
Reserved: 2010-07-14T00:00:00
Link: CVE-2010-2758
Vulnrichment
No data.
NVD
Status : Modified
Published: 2010-08-16T15:14:12.367
Modified: 2024-11-21T01:17:19.360
Link: CVE-2010-2758
Redhat
No data.