CVE Vulnerabilities

CVE-2001-0330

Published: Jun 27, 2001 | Modified: Oct 10, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Bugzilla 2.10 allows remote attackers to access sensitive information, including the database username and password, via an HTTP request for the globals.pl file, which is normally returned by the web server without being executed.

Affected Software

Name Vendor Start Version End Version
Bugzilla Mozilla 2.10 2.10
Bugzilla Mozilla 2.6 2.6
Bugzilla Mozilla 2.4 2.4
Bugzilla Mozilla 2.8 2.8

References