CVE-2002-0008: High severity Bugzilla vulnerability
Bugzilla before 2.14.1 allows remote attackers to (1) spoof a user comment via an HTTP request to processbug.cgi using the "who" parameter, instead of the Bugzillalogin cookie, or (2) post a bug as another user by modifying the reporter parameter to enterbug.cgi, which is passed to postbug.cgi.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2002-0008?
CVE-2002-0008 is considered a high severity vulnerability due to its exploitation potential for unauthorized access.
How do I fix CVE-2002-0008?
To fix CVE-2002-0008, upgrade Bugzilla to version 2.14.1 or later.
What types of attacks can CVE-2002-0008 facilitate?
CVE-2002-0008 can facilitate user comment spoofing and allow posting a bug as another user.
Which versions of Bugzilla are affected by CVE-2002-0008?
CVE-2002-0008 affects all Bugzilla versions prior to 2.14.1.
Can CVE-2002-0008 lead to data integrity issues?
Yes, exploitation of CVE-2002-0008 can lead to data integrity issues by allowing unauthorized modifications to bug reports.