Show filters
64 Total Results
Displaying 61-64 of 64
Sort by:
Attacker Value
Unknown
CVE-2002-0805
Disclosure Date: August 12, 2002 (last updated February 22, 2025)
Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, (1) creates new directories with world-writable permissions, and (2) creates the params file with world-writable permissions, which allows local users to modify the files and execute code.
0
Attacker Value
Unknown
CVE-2002-0807
Disclosure Date: August 12, 2002 (last updated February 22, 2025)
Cross-site scripting vulnerabilities in Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, could allow remote attackers to execute script as other Bugzilla users via the full name (real name) field, which is not properly quoted by editusers.cgi.
0
Attacker Value
Unknown
CVE-2002-0806
Disclosure Date: August 12, 2002 (last updated February 22, 2025)
Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, allows authenticated users with editing privileges to delete other users by directly calling the editusers.cgi script with the "del" option.
0
Attacker Value
Unknown
CVE-2002-0803
Disclosure Date: August 12, 2002 (last updated February 22, 2025)
Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, allows remote attackers to display restricted products and components via a direct HTTP request to queryhelp.cgi.
0