Title : Bugzilla "importxml.pl" Remote Directory Traversal Vulnerability VUPEN ID : VUPEN/ADV-2008-2344 CVE ID : CVE-2008-4437 CWE ID : CWE-22
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-08-12
Technical Description
A vulnerability has been identified in Bugzilla, which could be exploited by attackers to gain unauthorized access to arbitrary files on a vulnerable system. This issue is due to an input validation error in the "importxml.pl" script when processing the "filename" field while reading an XML file specified via the "--attach_path" option, which could be exploited to display the contents of arbitrary files via directory traversal attacks.