CVE-2008-4437
03.10.2008, 22:22
Directory traversal vulnerability in importxml.pl in Bugzilla before 2.22.5, and 3.x before 3.0.5, when --attach_path is enabled, allows remote attackers to read arbitrary files via an XML file with a .. (dot dot) in the data element.
Vendor | Product | Version |
---|---|---|
mozilla | bugzilla | 2.4 |
mozilla | bugzilla | 2.6 |
mozilla | bugzilla | 2.8 |
mozilla | bugzilla | 2.9 |
mozilla | bugzilla | 2.22.1 |
mozilla | bugzilla | 2.22.2 |
mozilla | bugzilla | 2.22.3 |
mozilla | bugzilla | 2.22.4 |
mozilla | bugzilla | 2.23 |
mozilla | bugzilla | 2.23.1 |
mozilla | bugzilla | 2.23.2 |
mozilla | bugzilla | 2.23.3 |
mozilla | bugzilla | 2.23.4 |
mozilla | bugzilla | 3.0.2 |
mozilla | bugzilla | 3.1.1 |
mozilla | bugzilla | 3.1.2 |
mozilla | bugzilla | 3.1.3 |
mozilla | bugzilla | 3.1.4 |
𝑥
= Vulnerable software versions

Ubuntu Releases
References