CVE-2012-0448 Information
Feb 14, 2021
cve
Description
Bugzilla 2.x and 3.x before 3.4.14 3.5.x and 3.6.x before 3.6.8 3.7.x and 4.0.x before 4.0.4 and 4.1.x and 4.2.x before 4.2rc2 does not reject non-ASCII characters in e-mail addresses of new user accounts which makes it easier for remote authenticated users to spoof other user accounts by choosing a similar e-mail address.
Reference
http://secunia.com/advisories/47814 http://www.bugzilla.org/security/3.4.13/ http://www.securityfocus.com/bid/51784 http://www.securitytracker.com/id?1026623 https://bugzilla.mozilla.org/show_bug.cgi?id=714472 https://exchange.xforce.ibmcloud.com/vulnerabilities/72877
Share on: