AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2007-0792

HIGH · CVSS 7.5 EPSS 1.32%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2007-02-06 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2007-0792
Severity
HIGH
CVSS
7.5
EPSS
1.32%
Apache

Original Filing — NVD Description

The mod_perl initialization script in Bugzilla 2.23.3 does not set the Bugzilla Apache configuration to allow .htaccess permissions to override file permissions, which allows remote attackers to obtain the database username and password via a direct request for the localconfig file.