Loading...
Loading...
Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt.
February 3, 2010
April 29, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2009-3989
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.