CVE-2004-0707

Bugzilla <2.16.6, 2.18-2.18rc1 - SQL Injection

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in editusers.cgi in Bugzilla 2.16.x before 2.16.6, and 2.18 before 2.18rc1, allows remote attackers with privileges to grant membership to any group to execute arbitrary SQL.

References (4)

Core 4
Core References
Issue Tracking x_refsource_confirm
http://bugzilla.mozilla.org/show_bug.cgi?id=244272
Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/10698
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=108965446813639&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/16668

Scores

EPSS 0.0103
EPSS Percentile 59.8%

Details

Status published
Products (24)
mozilla/bugzilla 2.4
mozilla/bugzilla 2.6
mozilla/bugzilla 2.8
mozilla/bugzilla 2.10
mozilla/bugzilla 2.12
mozilla/bugzilla 2.14
mozilla/bugzilla 2.14.1
mozilla/bugzilla 2.14.2
mozilla/bugzilla 2.14.3
mozilla/bugzilla 2.14.4
... and 14 more
Published Jul 27, 2004
Tracked Since Feb 18, 2026