CVE-2003-1043

Bugzilla <= 2.16.3 and 2.17.1-2.17.4 - Authenticated SQL Injection via editkeywords.cgi id Parameter

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in Bugzilla 2.16.3 and earlier, and 2.17.1 through 2.17.4, allows remote authenticated users with editkeywords privileges to execute arbitrary SQL via the id parameter to editkeywords.cgi.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/343185
Vendor Advisory vendor-advisory x_refsource_conectiva
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000774
Issue Tracking x_refsource_confirm
http://bugzilla.mozilla.org/show_bug.cgi?id=219044
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/13596
Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/8953

Scores

EPSS 0.0257
EPSS Percentile 83.5%

Details

Status published
Products (18)
mozilla/bugzilla 2.4
mozilla/bugzilla 2.6
mozilla/bugzilla 2.8
mozilla/bugzilla 2.10
mozilla/bugzilla 2.12
mozilla/bugzilla 2.14
mozilla/bugzilla 2.14.1
mozilla/bugzilla 2.14.2
mozilla/bugzilla 2.14.3
mozilla/bugzilla 2.14.4
... and 8 more
Published Aug 18, 2004
Tracked Since Feb 18, 2026