Security Advisory
CVE-2008-2104
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
The WebService in Bugzilla 3.1.3 allows remote authenticated users without canconfirm privileges to create NEW or ASSIGNED bug entries via a request to the XML-RPC interface, which bypasses the canconfirm check.