CVE-2008-2104

Publication date

2008-05-07 20:07:00

Family

mitre

State

PUBLISHED

Description

The WebService in Bugzilla 3.1.3 allows remote authenticated users without canconfirm privileges to create NEW or ASSIGNED bug entries via a request to the XML-RPC interface, which bypasses the canconfirm check.