CVE-2002-0810

Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, directs error messages from the syncshadowdb command to the HTML output, which could leak sensitive information, including plaintext passwords, if syncshadowdb fails.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:bugzilla:2.14:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.14.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.16:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.16:rc1:*:*:*:*:*:*

History

20 Nov 2024, 23:39

Type Values Removed Values Added
References () ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SN-02:05.asc - () ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SN-02:05.asc -
References () http://archives.neohapsis.com/archives/bugtraq/2002-06/0054.html - Patch, Vendor Advisory () http://archives.neohapsis.com/archives/bugtraq/2002-06/0054.html - Patch, Vendor Advisory
References () http://bugzilla.mozilla.org/show_bug.cgi?id=92263 - () http://bugzilla.mozilla.org/show_bug.cgi?id=92263 -
References () http://www.iss.net/security_center/static/9306.php - () http://www.iss.net/security_center/static/9306.php -
References () http://www.osvdb.org/6399 - () http://www.osvdb.org/6399 -
References () http://www.redhat.com/support/errata/RHSA-2002-109.html - () http://www.redhat.com/support/errata/RHSA-2002-109.html -
References () http://www.securityfocus.com/bid/4964 - () http://www.securityfocus.com/bid/4964 -

Information

Published : 2002-08-12 04:00

Updated : 2024-11-20 23:39


NVD link : CVE-2002-0810

Mitre link : CVE-2002-0810

CVE.ORG link : CVE-2002-0810


JSON object : View

Products Affected

mozilla

  • bugzilla