Directory traversal vulnerability in importxml.pl in Bugzilla before 2.22.5, and 3.x before 3.0.5, when --attach_path is enabled, allows remote attackers to read arbitrary files via an XML file with a .. (dot dot) in the data element.
                
            References
                    Configurations
                    Configuration 1 (hide)
            
            
  | 
    
History
                    No history.
Information
                Published : 2008-10-03 22:22
Updated : 2017-08-08 01:32
NVD link : CVE-2008-4437
Mitre link : CVE-2008-4437
CVE.ORG link : CVE-2008-4437
JSON object : View
Products Affected
                mozilla
- bugzilla
 
CWE
                
                    
                        
                        CWE-22
                        
            Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
