CVE-2003-1042

Bugzilla <= 2.16.3 - Authenticated SQL Injection via Product Name

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in collectstats.pl for Bugzilla 2.16.3 and earlier allows remote authenticated users with editproducts privileges to execute arbitrary SQL via the product name.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/343185
Vendor Advisory vendor-advisory x_refsource_conectiva
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000774
Issue Tracking x_refsource_confirm
http://bugzilla.mozilla.org/show_bug.cgi?id=214290
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/13594
Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/8953

Scores

EPSS 0.0257
EPSS Percentile 83.5%

Details

Status published
Products (18)
mozilla/bugzilla 2.4
mozilla/bugzilla 2.6
mozilla/bugzilla 2.8
mozilla/bugzilla 2.10
mozilla/bugzilla 2.12
mozilla/bugzilla 2.14
mozilla/bugzilla 2.14.1
mozilla/bugzilla 2.14.2
mozilla/bugzilla 2.14.3
mozilla/bugzilla 2.14.4
... and 8 more
Published Aug 18, 2004
Tracked Since Feb 18, 2026