CVE-2003-1045

Bugzilla <2.16.3, <2.17.1-2.17.4 - Info Disclosure

Title source: llm
STIX 2.1

Description

votes.cgi in Bugzilla 2.16.3 and earlier, and 2.17.1 through 2.17.4, allows remote attackers to read a user's voting page when that user has voted on a restricted bug, which allows remote attackers to read potentially sensitive voting information by modifying the who parameter.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/343185
Vendor Advisory vendor-advisory x_refsource_conectiva
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000774
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/13600
Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/8953
Patch, Vendor Advisory x_refsource_confirm
http://bugzilla.mozilla.org/show_bug.cgi?id=209376

Scores

EPSS 0.0121
EPSS Percentile 65.1%

Details

Status published
Products (18)
mozilla/bugzilla 2.4
mozilla/bugzilla 2.6
mozilla/bugzilla 2.8
mozilla/bugzilla 2.10
mozilla/bugzilla 2.12
mozilla/bugzilla 2.14
mozilla/bugzilla 2.14.1
mozilla/bugzilla 2.14.2
mozilla/bugzilla 2.14.3
mozilla/bugzilla 2.14.4
... and 8 more
Published Aug 18, 2004
Tracked Since Feb 18, 2026