CVE-2001-1403

Bugzilla - Credential Exposure via URL Parameter

Title source: llm
STIX 2.1

Description

Bugzilla before 2.14 includes the username and password in URLs, which could allow attackers to gain privileges by reading the information from the web server logs, or by "shoulder-surfing" and observing the web browser's location bar.

References (3)

Core 3
Core References
Issue Tracking x_refsource_confirm
http://bugzilla.mozilla.org/show_bug.cgi?id=15980
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=99912899900567
Patch, Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2001-107.html

Scores

EPSS 0.0113
EPSS Percentile 62.7%

Details

Status published
Products (6)
mozilla/bugzilla 2.4
mozilla/bugzilla 2.6
mozilla/bugzilla 2.8
mozilla/bugzilla 2.10
mozilla/bugzilla 2.12
mozilla/bugzilla 2.14
Published Sep 10, 2001
Tracked Since Feb 18, 2026