First published: Wed Jun 27 2001(Updated: )
Bugzilla 2.10 allows remote attackers to access sensitive information, including the database username and password, via an HTTP request for the globals.pl file, which is normally returned by the web server without being executed.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Bugzilla | =2.10 | |
Mozilla Bugzilla | =2.6 | |
Mozilla Bugzilla | =2.4 | |
Mozilla Bugzilla | =2.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0330 is classified as a medium severity vulnerability due to the potential access to sensitive data.
To fix CVE-2001-0330, ensure that the globals.pl file is not accessible via HTTP requests by configuring web server permissions.
CVE-2001-0330 affects Bugzilla versions 2.4, 2.6, 2.8, and 2.10.
CVE-2001-0330 can expose sensitive information such as the database username and password.
You can determine if your system is vulnerable to CVE-2001-0330 by attempting to access the globals.pl file through a web browser.