CVE-2002-0811: SQL Injection
Published Jul 31, 2002
·Updated
Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, may allow remote attackers to cause a denial of service or execute certain queries via a SQL injection attack on the sort order parameter to buglist.cgi.
Affected Software
4 affected components
Bugzilla=2.16-rc1
Bugzilla=2.16
Bugzilla=2.14.1
Bugzilla=2.14
Event History
Jul 31, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0811?
CVE-2002-0811 has a moderate severity rating due to the potential for denial of service and unauthorized query execution.
2
How do I fix CVE-2002-0811?
To fix CVE-2002-0811, upgrade Bugzilla to version 2.14.2 or 2.16rc2 or later.
3
Which versions of Bugzilla are affected by CVE-2002-0811?
CVE-2002-0811 affects Bugzilla versions 2.14 and 2.16 before their respective fixed versions.
4
What type of attack does CVE-2002-0811 facilitate?
CVE-2002-0811 facilitates SQL injection attacks through the sort order parameter in buglist.cgi.
5
Can CVE-2002-0811 be exploited remotely?
Yes, CVE-2002-0811 can be exploited remotely by attackers to perform denial of service or execute malicious queries.