CVE-2003-0013
published 2003-01-17CVE-2003-0013: The default .htaccess scripts for Bugzilla 2.14.x before 2.14.5, 2.16.x before 2.16.2, and 2.17.x before 2.17.3 do not include filenames for backup copies of…
PriorityP427high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.08%
79.6th percentile
The default .htaccess scripts for Bugzilla 2.14.x before 2.14.5, 2.16.x before 2.16.2, and 2.17.x before 2.17.3 do not include filenames for backup copies of the localconfig file that are made from editors such as vi and Emacs, which could allow remote attackers to obtain a database password by directly accessing the backup file.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://marc.info/?l=bugtraq&m=104154319200399&w=2http://www.debian.org/security/2003/dsa-230http://www.iss.net/security_center/static/10970.phphttp://www.osvdb.org/6351http://www.securityfocus.com/bid/6501http://marc.info/?l=bugtraq&m=104154319200399&w=2http://www.debian.org/security/2003/dsa-230http://www.iss.net/security_center/static/10970.phphttp://www.osvdb.org/6351http://www.securityfocus.com/bid/6501
2003-01-17
Published