Vulnerabilities > CVE-2002-0810 - Unspecified vulnerability in Mozilla Bugzilla 2.14/2.14.1/2.16

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
mozilla
nessus

Summary

Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, directs error messages from the syncshadowdb command to the HTML output, which could leak sensitive information, including plaintext passwords, if syncshadowdb fails.

Vulnerable Configurations

Part Description Count
Application
Mozilla
4

Nessus

NASL familyCGI abuses
NASL idBUGZILLA_VULNS.NASL
descriptionAccording to its version number, the remote Bugzilla bug tracking system is vulnerable to various flaws, including SQL injection, cross-site scripting, and arbitrary command execution.
last seen2020-06-01
modified2020-06-02
plugin id11463
published2003-03-24
reporterThis script is Copyright (C) 2003-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/11463
titleBugzilla < 2.14.2 / 2.16rc2 / 2.17 Multiple Vulnerabilities (SQLi, XSS, ID, Cmd Exe)

Redhat

advisories
rhsa
idRHSA-2002:109