7.5
CVSSv2

CVE-2003-0013

Published: 17/01/2003 Updated: 18/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The default .htaccess scripts for Bugzilla 2.14.x prior to 2.14.5, 2.16.x prior to 2.16.2, and 2.17.x prior to 2.17.3 do not include filenames for backup copies of the localconfig file that are made from editors such as vi and Emacs, which could allow remote malicious users to obtain a database password by directly accessing the backup file.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla bugzilla 2.14.2

mozilla bugzilla 2.14.3

mozilla bugzilla 2.14

mozilla bugzilla 2.14.1

mozilla bugzilla 2.17.1

mozilla bugzilla 2.16.1

mozilla bugzilla 2.17

mozilla bugzilla 2.14.4

mozilla bugzilla 2.16

Vendor Advisories

Two vulnerabilities have been discovered in Bugzilla, a web-based bug tracking system, by its authors The Common Vulnerabilities and Exposures Project identifies the following vulnerabilities: CAN-2003-0012 (BugTraq ID 6502) The provided data collection script intended to be run as a nightly cron job changes the permissions of the ...