Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2013-0786

The Bugzilla::Search::build_subselect function in Bugzilla 2.x and 3.x before 3.6.13 and 3.7.x and 4.0.x before 4.0.10 generates different error messages for invalid product queries depending on whether a product exists, which allows remote attackers to discover private product names by using debug mode for a query.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 51.4%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2013-0786


Contact Us

Shodan ® - All rights reserved