7.5
CVSSv2

CVE-2001-1401

Published: 10/09/2001 Updated: 18/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Bugzilla prior to 2.14 does not properly restrict access to confidential bugs, which could allow Bugzilla users to bypass viewing permissions via modified bug id parameters in (1) process_bug.cgi, (2) show_activity.cgi, (3) showvotes.cgi, (4) showdependencytree.cgi, (5) showdependencygraph.cgi, (6) showattachment.cgi, or (7) describecomponents.cgi.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla bugzilla 2.10

mozilla bugzilla 2.12

mozilla bugzilla 2.14

mozilla bugzilla 2.4

mozilla bugzilla 2.6

mozilla bugzilla 2.8