Bugzilla 2.x and 3.x through 3.6.11, 3.7.x and 4.0.x before 4.0.8, 4.1.x and 4.2.x before 4.2.3, and 4.3.x before 4.3.3 stores potentially sensitive information under the web root with insufficient access control, which allows remote attackers to read (1) template (aka .tmpl) files, (2) other custom extension files under extensions/, or (3) custom documentation files under docs/ via a direct request.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-10-03T16:15:33

Updated: 2022-10-03T16:15:33

Reserved: 2022-10-03T00:00:00


Link: CVE-2012-4747

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2012-09-04T11:04:50.357

Modified: 2012-09-04T11:04:50.357


Link: CVE-2012-4747

JSON object: View

cve-icon Redhat Information

No data.

CWE