VDB
CVE-2007-0792
CVE-2007-0792
PUBLISHED
CVSS 7.5 HIGH
The mod_perl initialization script in Bugzilla 2.23.3 does not set the Bugzilla Apache configuration to allow .htaccess permissions to override file permissions, which allows remote attackers to obtain the database username and password via a direct request for the localconfig file.
EPSS 0.96% · 76.9th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
0.96%
76.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | * |
| mozilla | bugzilla | 2.23.3 |
Timeline
- Feb 6, 2007 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 11, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Sep 26, 2023 EPSS Score
References
- http://www.securityfocus.com/bid/22380 technical
- 35862 vdb
- 2222 third-party-advisory
- 1017585 vdb
- 20070203 Security Advisory for Bugzilla 2.20.3, 2.22.1, and 2.23.3 mailing-list
- http://www.bugzilla.org/security/2.20.3/ url
- ADV-2007-0477 vdb
- bugzilla-htaccess-information-disclosure(32252) vdb
- https://nvd.nist.gov/vuln/detail/CVE-2007-0792 advisory
- http://www.bugzilla.org/security/2.20.3 url