2.1
CVSSv2

CVE-2003-0012

Published: 17/01/2003 Updated: 18/10/2016
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The data collection script for Bugzilla 2.14.x prior to 2.14.5, 2.16.x prior to 2.16.2, and 2.17.x prior to 2.17.3 sets world-writable permissions for the data/mining directory when it runs, which allows local users to modify or delete the data.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla bugzilla 2.14.4

mozilla bugzilla 2.16

mozilla bugzilla 2.14.1

mozilla bugzilla 2.14.2

mozilla bugzilla 2.14.3

mozilla bugzilla 2.14

mozilla bugzilla 2.17.1

mozilla bugzilla 2.16.1

mozilla bugzilla 2.17

Vendor Advisories

Two vulnerabilities have been discovered in Bugzilla, a web-based bug tracking system, by its authors The Common Vulnerabilities and Exposures Project identifies the following vulnerabilities: CAN-2003-0012 (BugTraq ID 6502) The provided data collection script intended to be run as a nightly cron job changes the permissions of the ...