Description
SQL injection vulnerability in editusers.cgi in Bugzilla 2.16.x before 2.16.6, and 2.18 before 2.18rc1, allows remote attackers with privileges to grant membership to any group to execute arbitrary SQL.
References (4)
Core 4
Core References
Issue Tracking x_refsource_confirm
http://bugzilla.mozilla.org/show_bug.cgi?id=244272
Patch, Vendor Advisory vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/10698
Mailing List mailing-list
x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=108965446813639&w=2
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/16668
Scores
EPSS
0.0103
EPSS Percentile
59.8%
Details
Status
published
Products (24)
mozilla/bugzilla
2.4
mozilla/bugzilla
2.6
mozilla/bugzilla
2.8
mozilla/bugzilla
2.10
mozilla/bugzilla
2.12
mozilla/bugzilla
2.14
mozilla/bugzilla
2.14.1
mozilla/bugzilla
2.14.2
mozilla/bugzilla
2.14.3
mozilla/bugzilla
2.14.4
... and 14 more
Published
Jul 27, 2004
Tracked Since
Feb 18, 2026