The WebService in Bugzilla 3.1.3 allows remote authenticated users without canconfirm privileges to create NEW or ASSIGNED bug entries via a request to the XML-RPC interface, which bypasses the canconfirm check.
                
            References
                    Configurations
                    History
                    No history.
Information
                Published : 2008-05-07 20:20
Updated : 2017-08-08 01:30
NVD link : CVE-2008-2104
Mitre link : CVE-2008-2104
CVE.ORG link : CVE-2008-2104
JSON object : View
Products Affected
                mozilla
- bugzilla
 
CWE
                
                    
                        
                        CWE-264
                        
            Permissions, Privileges, and Access Controls
