CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4402 | CVE-2002-0008 | Candidate | Bugzilla before 2.14.1 allows remote attackers to (1) spoof a user comment via an HTTP request to process_bug.cgi using the "who" parameter, instead of the Bugzilla_login cookie, or (2) post a bug as another user by modifying the reporter parameter to enter_bug.cgi, which is passed to post_bug.cgi. | Modified (20050703) | ACCEPT(3) Baker, Cole, Green | MODIFY(1) Frech | NOOP(2) Foat, Wall | Frech> XF:bugzilla-processbug-comment-spoofing(7805) | XF:bugzilla-postbug-report-spoofing(7804) | View |
4207 | CVE-2001-1404 | Candidate | Bugzilla before 2.14 stores user passwords in plaintext and sends password requests in an email message, which could allow attackers to gain privileges. | Proposed (20020830) | ACCEPT(6) Armstrong, Baker, Cole, Cox, Green, Wall | MODIFY(1) Frech | NOOP(1) Foat | Frech> XF:bugzilla-plaintext-passwords(10483) | View |
4206 | CVE-2001-1403 | Candidate | Bugzilla before 2.14 includes the username and password in URLs, which could allow attackers to gain privileges by reading the information from the web server logs, or by "shoulder-surfing" and observing the web browser"s location bar. | Proposed (20020830) | ACCEPT(6) Armstrong, Baker, Cole, Cox, Green, Wall | MODIFY(1) Frech | NOOP(1) Foat | Frech> XF:bugzilla-location-bar-passwords(10484) | View |
4204 | CVE-2001-1401 | Candidate | Bugzilla before 2.14 does not properly restrict access to confidential bugs, which could allow Bugzilla users to bypass viewing permissions via modified bug id parameters in (1) process_bug.cgi, (2) show_activity.cgi, (3) showvotes.cgi, (4) showdependencytree.cgi, (5) showdependencygraph.cgi, (6) showattachment.cgi, or (7) describecomponents.cgi. | Proposed (20020830) | ACCEPT(6) Armstrong, Baker, Cole, Cox, Green, Wall | MODIFY(1) Frech | NOOP(1) Foat | Frech> XF:bugzilla-describe-components(7058) | XF:bugzilla-show-dependency-graph(7060) | XF:bugzilla-show-dependency-tree(7061) | XF:bugzilla-show-votes(7065) | XF:bugzilla-show-activity(7066) | XF:bugzilla-process-bug(7067) | XF:bugzilla-show-attachment(7070) | View |
4205 | CVE-2001-1402 | Candidate | Bugzilla before 2.14 does not properly escape untrusted parameters, which could allow remote attackers to conduct unauthorized activities via cross-site scripting (CSS) and possibly SQL injection attacks on (1) the product or output form variables for reports.cgi, (2) the voteon, bug_id, and user variables for showvotes.cgi, (3) an invalid email address in createaccount.cgi, (4) an invalid ID in showdependencytree.cgi, (5) invalid usernames and other fields in process_bug.cgi, and (6) error messages in buglist.cgi. | Proposed (20020830) | ACCEPT(6) Armstrong, Baker, Cole, Cox, Green, Wall | MODIFY(1) Frech | NOOP(1) Foat | Frech> XF:bugzilla-create-account-crosssite(7062) | XF:bugzilla-show-votes-crosssite(7063) | XF:bugzilla-reports-crosssite(7064) | XF:bugzilla-showdependencytree-xss(10482) | XF:bugzilla-processbug-xss(10485) | XF:bugzilla-buglist-displayerror-xss(10480) | View |
Page 198 of 20943, showing 5 records out of 104715 total, starting on record 986, ending on 990