Vulnerabilities > CVE-2003-1046 - Multiple vulnerability in Bugzilla

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
mozilla
nessus

Summary

describecomponents.cgi in Bugzilla 2.17.3 and 2.17.4 does not properly verify group membership when bug entry groups are used, which allows remote attackers to list component descriptions for otherwise restricted products.

Nessus

NASL familyCGI abuses
NASL idBUGZILLA_SQL_VULNS.NASL
descriptionAccording to its version number, the remote Bugzilla bug tracker is vulnerable to various flaws that could let a privileged user execute arbitrary SQL commands on this host, which could allow an attacker to obtain information about bugs marked as being confidential.
last seen2020-06-01
modified2020-06-02
plugin id11917
published2003-11-05
reporterThis script is Copyright (C) 2003-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/11917
titleBugzilla < 2.16.4 / 2.17.5 Multiple Vulnerabilities (SQLi, ID)