Description
Bugzilla before 2.14 includes the username and password in URLs, which could allow attackers to gain privileges by reading the information from the web server logs, or by "shoulder-surfing" and observing the web browser's location bar.
Affected products
- Mozilla / Bugzilla2.4 – 2.4
- Mozilla / Bugzilla2.6 – 2.6
- Mozilla / Bugzilla2.8 – 2.8
- Mozilla / Bugzilla2.10 – 2.10
- Mozilla / Bugzilla2.12 – 2.12
- Mozilla / Bugzilla2.14 – 2.14