CVE-2004-0706

Bugzilla 2.17.5-2.17.7 - Password Exposure via Image URL Embedding

Title source: llm
STIX 2.1

Description

Bugzilla 2.17.5 through 2.17.7 embeds the password in an image URL, which could allow local users to view the password in the web server log files.

References (4)

Core 4
Core References
Issue Tracking x_refsource_confirm
http://bugzilla.mozilla.org/show_bug.cgi?id=235510
Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/10698
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=108965446813639&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/16669

Scores

EPSS 0.0029
EPSS Percentile 21.3%

Details

Status published
Products (24)
mozilla/bugzilla 2.4
mozilla/bugzilla 2.6
mozilla/bugzilla 2.8
mozilla/bugzilla 2.10
mozilla/bugzilla 2.12
mozilla/bugzilla 2.14
mozilla/bugzilla 2.14.1
mozilla/bugzilla 2.14.2
mozilla/bugzilla 2.14.3
mozilla/bugzilla 2.14.4
... and 14 more
Published Jul 27, 2004
Tracked Since Feb 18, 2026