Bugzilla 2.17.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 generates different error messages depending on whether a product exists, which makes it easier for remote attackers to guess product names via unspecified use of the (1) Reports or (2) Duplicates page.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2010-08-13T19:00:00

Updated: 2024-08-07T02:46:48.196Z

Reserved: 2010-07-14T00:00:00

Link: CVE-2010-2758

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2010-08-16T15:14:12.367

Modified: 2010-09-08T05:48:51.287

Link: CVE-2010-2758

cve-icon Redhat

No data.