Title : Bugzilla "offer_account_by_email()" Arbitrary Account Creation Weakness VUPEN ID : VUPEN/ADV-2007-3200 CVE ID : CVE-2007-5038
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-09-19
Technical Description
A weakness has been identified in Bugzilla, which could be exploited by attackers to bypass security restrictions. This issue is caused by an error in the "offer_account_by_email()" [WebService/User.pm] function that does not properly validate the "createemailregexp" parameter, which could be exploited by malicious people to create user accounts on a system with the SOAP::Lite Perl module installed even when the account creation feature is disabled.