CVE-2002-0007
published 2002-01-31CVE-2002-0007: CGI.pl in Bugzilla before 2.14.1, when using LDAP, allows remote attackers to obtain an anonymous bind to the LDAP server via a request that does not include a…
PriorityP432critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
2.37%
81.9th percentile
CGI.pl in Bugzilla before 2.14.1, when using LDAP, allows remote attackers to obtain an anonymous bind to the LDAP server via a request that does not include a password, which causes a null password to be sent to the LDAP server.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | bugzilla | <= 2.14.1 | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
security flaw
vendor_redhat·2002-01-05·CVSS 10.0
CVE-2002-0007 [CRITICAL] security flaw
security flaw
CGI.pl in Bugzilla before 2.14.1, when using LDAP, allows remote attackers to obtain an anonymous bind to the LDAP server via a request that does not include a password, which causes a null password to be sent to the LDAP server.
GHSA
GHSA-xmjv-5hmh-hg5p: CGI
ghsa_unreviewed·2022-04-30
CVE-2002-0007 [HIGH] GHSA-xmjv-5hmh-hg5p: CGI
CGI.pl in Bugzilla before 2.14.1, when using LDAP, allows remote attackers to obtain an anonymous bind to the LDAP server via a request that does not include a password, which causes a null password to be sent to the LDAP server.
No detection rules found.
No public exploits indexed.
http://archives.neohapsis.com/archives/bugtraq/2002-01/0034.htmlhttp://bugzilla.mozilla.org/show_bug.cgi?id=54901http://rhn.redhat.com/errata/RHSA-2002-001.htmlhttp://www.bugzilla.org/security2_14_1.htmlhttp://www.securityfocus.com/bid/3792https://exchange.xforce.ibmcloud.com/vulnerabilities/7812http://archives.neohapsis.com/archives/bugtraq/2002-01/0034.htmlhttp://bugzilla.mozilla.org/show_bug.cgi?id=54901http://rhn.redhat.com/errata/RHSA-2002-001.htmlhttp://www.bugzilla.org/security2_14_1.htmlhttp://www.securityfocus.com/bid/3792https://exchange.xforce.ibmcloud.com/vulnerabilities/7812
2002-01-31
Published