CVE
- Id
- 4206
- CVE No.
- CVE-2001-1403
- Status
- Candidate
- Description
- Bugzilla before 2.14 includes the username and password in URLs, which could allow attackers to gain privileges by reading the information from the web server logs, or by "shoulder-surfing" and observing the web browser"s location bar.
- Phase
- Proposed (20020830)
- Votes
- ACCEPT(6) Armstrong, Baker, Cole, Cox, Green, Wall | MODIFY(1) Frech | NOOP(1) Foat
- Comments
- Frech> XF:bugzilla-location-bar-passwords(10484)