CVE-2001-1402: SQL Injection
Bugzilla before 2.14 does not properly escape untrusted parameters, which could allow remote attackers to conduct unauthorized activities via cross-site scripting (CSS) and possibly SQL injection attacks on (1) the product or output form variables for reports.cgi, (2) the voteon, bugid, and user variables for showvotes.cgi, (3) an invalid email address in createaccount.cgi, (4) an invalid ID in showdependencytree.cgi, (5) invalid usernames and other fields in processbug.cgi, and (6) error messages in buglist.cgi.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2001-1402?
CVE-2001-1402 has a medium severity rating due to its potential for cross-site scripting and possibly SQL injection vulnerabilities.
How do I fix CVE-2001-1402?
To fix CVE-2001-1402, upgrade Bugzilla to version 2.14 or later, where the issue has been addressed.
What versions of Bugzilla are affected by CVE-2001-1402?
Bugzilla versions prior to 2.14, including 2.10, 2.6, 2.4, 2.12, and 2.8, are affected by CVE-2001-1402.
What types of attacks are possible with CVE-2001-1402?
CVE-2001-1402 could allow attackers to perform cross-site scripting (XSS) and possibly SQL injection attacks.
Is user data at risk with CVE-2001-1402?
Yes, user data could be at risk due to the vulnerabilities associated with CVE-2001-1402.