CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
7866 | CVE-2003-1042 | Candidate | SQL injection vulnerability in collectstats.pl for Bugzilla 2.16.3 and earlier allows remote authenticated users with editproducts privileges to execute arbitrary SQL via the product name. | Assigned (20040527) | None (candidate not yet proposed) | View | |
7867 | CVE-2003-1043 | Candidate | SQL injection vulnerability in Bugzilla 2.16.3 and earlier, and 2.17.1 through 2.17.4, allows remote authenticated users with editkeywords privileges to execute arbitrary SQL via the id parameter to editkeywords.cgi. | Assigned (20040527) | None (candidate not yet proposed) | View | |
7868 | CVE-2003-1044 | Candidate | editproducts.cgi in Bugzilla 2.16.3 and earlier, when usebuggroups is enabled, does not properly remove group add privileges from a group that is being deleted, which allows users with those privileges to perform unauthorized additions to the next group that is assigned with the original group ID. | Assigned (20040527) | None (candidate not yet proposed) | View | |
7869 | CVE-2003-1045 | Candidate | votes.cgi in Bugzilla 2.16.3 and earlier, and 2.17.1 through 2.17.4, allows remote attackers to read a user"s voting page when that user has voted on a restricted bug, which allows remote attackers to read potentially sensitive voting information by modifying the who parameter. | Assigned (20040527) | None (candidate not yet proposed) | View | |
7870 | CVE-2003-1046 | Candidate | describecomponents.cgi in Bugzilla 2.17.3 and 2.17.4 does not properly verify group membership when bug entry groups are used, which allows remote attackers to list component descriptions for otherwise restricted products. | Assigned (20040527) | None (candidate not yet proposed) | View |
Page 871 of 20943, showing 5 records out of 104715 total, starting on record 4351, ending on 4355