CVE-2011-3669 Information

Description

Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 2.x 3.x and 4.x before 4.2rc1 allows remote attackers to hijack the authentication of arbitrary users for requests that upload attachments.

Reference

http://secunia.com/advisories/47368 http://www.bugzilla.org/security/3.4.12/ https://bugzilla.mozilla.org/show_bug.cgi?id=703983

Share on: