CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
9135 | CVE-2004-0707 | Candidate | SQL injection vulnerability in editusers.cgi in Bugzilla 2.16.x before 2.16.6, and 2.18 before 2.18rc1, allows remote attackers with privileges to grant membership to any group to execute arbitrary SQL. | Assigned (20040720) | None (candidate not yet proposed) | View | |
9134 | CVE-2004-0706 | Candidate | Bugzilla 2.17.5 through 2.17.7 embeds the password in an image URL, which could allow local users to view the password in the web server log files. | Assigned (20040720) | None (candidate not yet proposed) | View | |
9133 | CVE-2004-0705 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in (1) editcomponents.cgi, (2) editgroups.cgi, (3) editmilestones.cgi, (4) editproducts.cgi, (5) editusers.cgi, and (6) editversions.cgi in Bugzilla 2.16.x before 2.16.6, and 2.18 before 2.18rc1, allow remote attackers to execute arbitrary JavaScript as other users via a URL parameter. | Assigned (20040720) | None (candidate not yet proposed) | View | |
9132 | CVE-2004-0704 | Candidate | Unknown vulnerability in (1) duplicates.cgi and (2) buglist.cgi in Bugzilla 2.16.x before 2.16.6, 2.18 before 2.18rc1, when configured to hide products, allows remote attackers to view hidden products. | Assigned (20040720) | None (candidate not yet proposed) | View | |
9131 | CVE-2004-0703 | Candidate | Unknown vulnerability in the administrative controls in Bugzilla 2.17.1 through 2.17.7 allows users with "grant membership" privileges to grant memberships to groups that the user does not control. | Assigned (20040720) | None (candidate not yet proposed) | View |
Page 19117 of 20943, showing 5 records out of 104715 total, starting on record 95581, ending on 95585