CVE Vulnerabilities

CVE-2002-1198

Published: Oct 28, 2002 | Modified: Oct 18, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Bugzilla 2.16.x before 2.16.1 does not properly filter apostrophes from an email address during account creation, which allows remote attackers to execute arbitrary SQL via a SQL injection attack.

Affected Software

Name Vendor Start Version End Version
Bugzilla Mozilla 2.14 (including) 2.14 (including)
Bugzilla Mozilla 2.14.1 (including) 2.14.1 (including)
Bugzilla Mozilla 2.14.2 (including) 2.14.2 (including)
Bugzilla Mozilla 2.14.3 (including) 2.14.3 (including)
Bugzilla Mozilla 2.14.4 (including) 2.14.4 (including)
Bugzilla Mozilla 2.16 (including) 2.16 (including)

References