CVE Vulnerabilities

CVE-2003-1042

Published: Aug 18, 2004 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

SQL injection vulnerability in collectstats.pl for Bugzilla 2.16.3 and earlier allows remote authenticated users with editproducts privileges to execute arbitrary SQL via the product name.

Affected Software

Name Vendor Start Version End Version
Bugzilla Mozilla 2.4 (including) 2.4 (including)
Bugzilla Mozilla 2.6 (including) 2.6 (including)
Bugzilla Mozilla 2.8 (including) 2.8 (including)
Bugzilla Mozilla 2.10 (including) 2.10 (including)
Bugzilla Mozilla 2.12 (including) 2.12 (including)
Bugzilla Mozilla 2.14 (including) 2.14 (including)
Bugzilla Mozilla 2.14.1 (including) 2.14.1 (including)
Bugzilla Mozilla 2.14.2 (including) 2.14.2 (including)
Bugzilla Mozilla 2.14.3 (including) 2.14.3 (including)
Bugzilla Mozilla 2.14.4 (including) 2.14.4 (including)
Bugzilla Mozilla 2.14.5 (including) 2.14.5 (including)
Bugzilla Mozilla 2.16 (including) 2.16 (including)
Bugzilla Mozilla 2.16.1 (including) 2.16.1 (including)
Bugzilla Mozilla 2.16.2 (including) 2.16.2 (including)
Bugzilla Mozilla 2.16.3 (including) 2.16.3 (including)
Bugzilla Mozilla 2.17.1 (including) 2.17.1 (including)
Bugzilla Mozilla 2.17.3 (including) 2.17.3 (including)
Bugzilla Mozilla 2.17.4 (including) 2.17.4 (including)

References