7.5
CVSSv2

CVE-2001-1403

Published: 10/09/2001 Updated: 18/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Bugzilla prior to 2.14 includes the username and password in URLs, which could allow malicious users to gain privileges by reading the information from the web server logs, or by "shoulder-surfing" and observing the web browser's location bar.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla bugzilla 2.14

mozilla bugzilla 2.4

mozilla bugzilla 2.10

mozilla bugzilla 2.12

mozilla bugzilla 2.6

mozilla bugzilla 2.8