CVE Vulnerabilities

CVE-2002-0807

Published: Aug 12, 2002 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Cross-site scripting vulnerabilities in Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, could allow remote attackers to execute script as other Bugzilla users via the full name (real name) field, which is not properly quoted by editusers.cgi.

Affected Software

NameVendorStart VersionEnd Version
BugzillaMozilla2.14 (including)2.14 (including)
BugzillaMozilla2.14.1 (including)2.14.1 (including)
BugzillaMozilla2.16 (including)2.16 (including)
BugzillaMozilla2.16-rc1 (including)2.16-rc1 (including)
Red Hat Powertools 7.0RedHat*
Red Hat Powertools 7.1RedHat*

References