CVE List

Id CVE No. Status Description Phase Votes Comments Actions
7866  CVE-2003-1042  Candidate  SQL injection vulnerability in collectstats.pl for Bugzilla 2.16.3 and earlier allows remote authenticated users with editproducts privileges to execute arbitrary SQL via the product name.  Assigned (20040527)  None (candidate not yet proposed)    View
7867  CVE-2003-1043  Candidate  SQL injection vulnerability in Bugzilla 2.16.3 and earlier, and 2.17.1 through 2.17.4, allows remote authenticated users with editkeywords privileges to execute arbitrary SQL via the id parameter to editkeywords.cgi.  Assigned (20040527)  None (candidate not yet proposed)    View
7868  CVE-2003-1044  Candidate  editproducts.cgi in Bugzilla 2.16.3 and earlier, when usebuggroups is enabled, does not properly remove group add privileges from a group that is being deleted, which allows users with those privileges to perform unauthorized additions to the next group that is assigned with the original group ID.  Assigned (20040527)  None (candidate not yet proposed)    View
7869  CVE-2003-1045  Candidate  votes.cgi in Bugzilla 2.16.3 and earlier, and 2.17.1 through 2.17.4, allows remote attackers to read a user"s voting page when that user has voted on a restricted bug, which allows remote attackers to read potentially sensitive voting information by modifying the who parameter.  Assigned (20040527)  None (candidate not yet proposed)    View
7870  CVE-2003-1046  Candidate  describecomponents.cgi in Bugzilla 2.17.3 and 2.17.4 does not properly verify group membership when bug entry groups are used, which allows remote attackers to list component descriptions for otherwise restricted products.  Assigned (20040527)  None (candidate not yet proposed)    View

Page 871 of 20943, showing 5 records out of 104715 total, starting on record 4351, ending on 4355

Actions