CVE-2011-0046

N/A Unknown
Published: January 28, 2011 Modified: April 29, 2026
View on NVD

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in Bugzilla before 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and 4.0.x before 4.0rc2 allow remote attackers to hijack the authentication of arbitrary users for requests related to (1) adding a saved search in buglist.cgi, (2) voting in votes.cgi, (3) sanity checking in sanitycheck.cgi, (4) creating or editing a chart in chart.cgi, (5) column changing in colchange.cgi, and (6) adding, deleting, or approving a quip in quips.cgi.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://osvdb.org/70705
Source: cve@mitre.org
http://osvdb.org/70706
Source: cve@mitre.org
http://osvdb.org/70707
Source: cve@mitre.org
http://osvdb.org/70708
Source: cve@mitre.org
http://osvdb.org/70709
Source: cve@mitre.org
http://osvdb.org/70710
Source: cve@mitre.org
http://secunia.com/advisories/43033
Source: cve@mitre.org
Vendor Advisory
http://www.bugzilla.org/security/3.2.9/
Source: cve@mitre.org
Vendor Advisory
http://www.vupen.com/english/advisories/2011/0207
Source: cve@mitre.org
Vendor Advisory
http://osvdb.org/70705
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/70706
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/70707
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/70708
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/70709
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/70710
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/43033
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/43165
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.bugzilla.org/security/3.2.9/
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://www.debian.org/security/2011/dsa-2322
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/45982
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2011/0207
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://www.vupen.com/english/advisories/2011/0271
Source: af854a3a-2127-422b-91ae-364da2661108
https://bugzilla.mozilla.org/show_bug.cgi?id=621090
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
https://bugzilla.mozilla.org/show_bug.cgi?id=621105
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
https://bugzilla.mozilla.org/show_bug.cgi?id=621107
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
https://bugzilla.mozilla.org/show_bug.cgi?id=621108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
https://bugzilla.mozilla.org/show_bug.cgi?id=621109
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
https://bugzilla.mozilla.org/show_bug.cgi?id=621110
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/65003
Source: af854a3a-2127-422b-91ae-364da2661108

44 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
1.1%
62th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

mozilla