First published: Thu Jan 10 2002(Updated: )
Bugzilla before 2.14.1 allows remote attackers to (1) spoof a user comment via an HTTP request to process_bug.cgi using the "who" parameter, instead of the Bugzilla_login cookie, or (2) post a bug as another user by modifying the reporter parameter to enter_bug.cgi, which is passed to post_bug.cgi.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Bugzilla | <=2.14.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0008 is considered a high severity vulnerability due to its exploitation potential for unauthorized access.
To fix CVE-2002-0008, upgrade Bugzilla to version 2.14.1 or later.
CVE-2002-0008 can facilitate user comment spoofing and allow posting a bug as another user.
CVE-2002-0008 affects all Bugzilla versions prior to 2.14.1.
Yes, exploitation of CVE-2002-0008 can lead to data integrity issues by allowing unauthorized modifications to bug reports.