CVE-2003-1042
Bugzilla <= 2.16.3 - Authenticated SQL Injection via Product Name
Title source: llmDescription
SQL injection vulnerability in collectstats.pl for Bugzilla 2.16.3 and earlier allows remote authenticated users with editproducts privileges to execute arbitrary SQL via the product name.
References (5)
Core 5
Core References
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/343185
Vendor Advisory vendor-advisory
x_refsource_conectiva
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000774
Issue Tracking x_refsource_confirm
http://bugzilla.mozilla.org/show_bug.cgi?id=214290
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/13594
Patch, Vendor Advisory vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/8953
Scores
EPSS
0.0257
EPSS Percentile
83.5%
Details
Status
published
Products (18)
mozilla/bugzilla
2.4
mozilla/bugzilla
2.6
mozilla/bugzilla
2.8
mozilla/bugzilla
2.10
mozilla/bugzilla
2.12
mozilla/bugzilla
2.14
mozilla/bugzilla
2.14.1
mozilla/bugzilla
2.14.2
mozilla/bugzilla
2.14.3
mozilla/bugzilla
2.14.4
... and 8 more
Published
Aug 18, 2004
Tracked Since
Feb 18, 2026