SQL injection vulnerability in the Bug.search WebService function in Bugzilla 3.3.2 through 3.4.1, and 3.5, allows remote attackers to execute arbitrary SQL commands via unspecified parameters.
| Software | From | Fixed in |
|---|---|---|
| mozilla / bugzilla | 3.3.2 | 3.3.2.x |
| mozilla / bugzilla | 3.3.4 | 3.3.4.x |
| mozilla / bugzilla | 3.5 | 3.5.x |
| mozilla / bugzilla | 3.4.1 | 3.4.1.x |
| mozilla / bugzilla | 3.3.3 | 3.3.3.x |
| mozilla / bugzilla | 3.4 | 3.4.x |