Total vulnerabilities in the database
email_in.pl in Bugzilla 2.23.4 through 3.0.0 allows remote attackers to execute arbitrary commands via the -f (From address) option to the Email::Send::Sendmail function, probably involving shell metacharacters.
Software | From | Fixed in |
---|---|---|
mozilla / bugzilla | 3.0.0 | 3.0.0.x |
mozilla / bugzilla | 2.23.4 | 2.23.4.x |
mozilla / bugzilla | 2.6 | 2.6.x |
mozilla / bugzilla | 2.4 | 2.4.x |
mozilla / bugzilla | 2.8 | 2.8.x |
mozilla / bugzilla | 2.9 | 2.9.x |