Loading...
Loading...
Bugzilla 2.x and 3.x through 3.6.11, 3.7.x and 4.0.x before 4.0.8, 4.1.x and 4.2.x before 4.2.3, and 4.3.x before 4.3.3 stores potentially sensitive information under the web root with insufficient access control, which allows remote attackers to read (1) template (aka .tmpl) files, (2) other custom extension files under extensions/, or (3) custom documentation files under docs/ via a direct request.
September 4, 2012
April 29, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2012-4747
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.