CVE-2002-0806

Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, allows authenticated users with editing privileges to delete other users by directly calling the editusers.cgi script with the "del" option.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:bugzilla:2.14:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.14.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.16:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.16:rc1:*:*:*:*:*:*

History

20 Nov 2024, 23:39

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/bugtraq/2002-06/0054.html - Patch, Vendor Advisory () http://archives.neohapsis.com/archives/bugtraq/2002-06/0054.html - Patch, Vendor Advisory
References () http://bugzilla.mozilla.org/show_bug.cgi?id=141557 - () http://bugzilla.mozilla.org/show_bug.cgi?id=141557 -
References () http://www.iss.net/security_center/static/9303.php - () http://www.iss.net/security_center/static/9303.php -
References () http://www.osvdb.org/5080 - () http://www.osvdb.org/5080 -
References () http://www.redhat.com/support/errata/RHSA-2002-109.html - () http://www.redhat.com/support/errata/RHSA-2002-109.html -
References () http://www.securityfocus.com/bid/4964 - () http://www.securityfocus.com/bid/4964 -

Information

Published : 2002-08-12 04:00

Updated : 2024-11-20 23:39


NVD link : CVE-2002-0806

Mitre link : CVE-2002-0806

CVE.ORG link : CVE-2002-0806


JSON object : View

Products Affected

mozilla

  • bugzilla