CVE Published: 24/02/2013 |
CVE Updated: 06/08/2024 |
CVE Year: 2013 Source: mozilla |
Vendor: n/a |
Product: n/a Status : PUBLISHED
CVE-2013-0786 Description
The Bugzilla::Search::build_subselect function in Bugzilla 2.x and 3.x before 3.6.13 and 3.7.x and 4.0.x before 4.0.10 generates different error messages for invalid product queries depending on whether a product exists, which allows remote attackers to discover private product names by using debug mode for a query.