Vulnerabilities > CVE-2002-0007 - Authentication Bypass vulnerability in BugZilla LDAP
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
CGI.pl in Bugzilla before 2.14.1, when using LDAP, allows remote attackers to obtain an anonymous bind to the LDAP server via a request that does not include a password, which causes a null password to be sent to the LDAP server.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 11 |
Redhat
advisories |
|
References
- http://archives.neohapsis.com/archives/bugtraq/2002-01/0034.html
- http://bugzilla.mozilla.org/show_bug.cgi?id=54901
- http://rhn.redhat.com/errata/RHSA-2002-001.html
- http://www.bugzilla.org/security2_14_1.html
- http://www.securityfocus.com/bid/3792
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7812