CVE-2002-0009Mozilla Bugzilla vulnerability

6 documents6 sources
Severity
5.0MEDIUMNVD
EPSS
0.9%
top 24.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 31
Latest updateApr 30

Description

show_bug.cgi in Bugzilla before 2.14.1 allows a user with "Bugs Access" privileges to see other products that are not accessible to the user, by submitting a bug and reading the resulting Product pulldown menu.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDmozilla/bugzilla2.14.1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-m9mc-j7jm-3wgj: show_bug2022-04-30
CVEList
CVE-2002-0009: show_bug2003-04-02

💥Exploits & PoCs

1
Exploit-DB
PuTTy.exe 0.53 - Remote Buffer Overflow (Metasploit)2010-06-15

📋Vendor Advisories

1
Red Hat
security flaw2002-01-05

💬Community

1
Bugzilla
CVE-2002-0009 security flaw2018-08-16
CVE-2002-0009 — Mozilla Bugzilla vulnerability | cvebase