CVE-2004-0702

Bugzilla 2.17.1-2.17.7 - Database Password Exposure via Error Message

Title source: llm
STIX 2.1

Description

DBI in Bugzilla 2.17.1 through 2.17.7 displays the database password in an error message when the SQL server is not running, which could allow remote attackers to gain sensitive information.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/16673
Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/10698
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=108965446813639&w=2

Scores

EPSS 0.0120
EPSS Percentile 64.7%

Details

Status published
Products (24)
mozilla/bugzilla 2.4
mozilla/bugzilla 2.6
mozilla/bugzilla 2.8
mozilla/bugzilla 2.10
mozilla/bugzilla 2.12
mozilla/bugzilla 2.14
mozilla/bugzilla 2.14.1
mozilla/bugzilla 2.14.2
mozilla/bugzilla 2.14.3
mozilla/bugzilla 2.14.4
... and 14 more
Published Jul 27, 2004
Tracked Since Feb 18, 2026