Bugzilla 2.17.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 generates different error messages depending on whether a product exists, which makes it easier for remote attackers to guess product names via unspecified use of the (1) Reports or (2) Duplicates page.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2010-08-16 15:14
Updated : 2024-02-04 17:54
NVD link : CVE-2010-2758
Mitre link : CVE-2010-2758
CVE.ORG link : CVE-2010-2758
JSON object : View
Products Affected
mozilla
- bugzilla
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor