CVE-2001-0330: High severity Bugzilla vulnerability
Bugzilla 2.10 allows remote attackers to access sensitive information, including the database username and password, via an HTTP request for the globals.pl file, which is normally returned by the web server without being executed.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2001-0330?
CVE-2001-0330 is classified as a medium severity vulnerability due to the potential access to sensitive data.
How do I fix CVE-2001-0330?
To fix CVE-2001-0330, ensure that the globals.pl file is not accessible via HTTP requests by configuring web server permissions.
What versions of Bugzilla are affected by CVE-2001-0330?
CVE-2001-0330 affects Bugzilla versions 2.4, 2.6, 2.8, and 2.10.
What kind of information can be exposed by CVE-2001-0330?
CVE-2001-0330 can expose sensitive information such as the database username and password.
How can I determine if my system is vulnerable to CVE-2001-0330?
You can determine if your system is vulnerable to CVE-2001-0330 by attempting to access the globals.pl file through a web browser.