FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2009-3166

This CVE name corresponds to:

Entered Topic
2009-09-17 bugzilla -- two SQL injections, sensitive data exposure

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2009-3166
Phase Assigned(20090911)

Description

token.cgi in Bugzilla 3.4rc1 through 3.4.1 places a password in a URL at the beginning of a login session that occurs immediately after a password reset, which allows context-dependent attackers to discover passwords by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.

References

Source Reference
CONFIRM http://www.bugzilla.org/security/3.0.8/
CONFIRM https://bugzilla.mozilla.org/show_bug.cgi?id=508189
BID 36372
SECTRACK 1022902
SECUNIA 36718