CVE-2002-1198: SQL Injection
Published Oct 28, 2002
·Updated
Bugzilla 2.16.x before 2.16.1 does not properly filter apostrophes from an email address during account creation, which allows remote attackers to execute arbitrary SQL via a SQL injection attack.
Affected Software
6 affected components
Bugzilla=2.14
Bugzilla=2.14.1
Bugzilla=2.14.2
Bugzilla=2.14.3
Bugzilla=2.14.4
Bugzilla=2.16
Event History
Oct 28, 2002
CVE Published
05:00 AM
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1198?
CVE-2002-1198 is considered a high severity vulnerability due to the potential for remote SQL injection attacks.
2
How do I fix CVE-2002-1198?
To fix CVE-2002-1198, upgrade Bugzilla to version 2.16.1 or later and ensure proper input sanitization.
3
What systems are affected by CVE-2002-1198?
CVE-2002-1198 affects Bugzilla versions 2.14.x and 2.16.x prior to 2.16.1.
4
What type of vulnerability is CVE-2002-1198?
CVE-2002-1198 is a SQL injection vulnerability that occurs during account creation due to improper filtering of email input.
5
Can CVE-2002-1198 lead to data compromise?
Yes, CVE-2002-1198 can lead to unauthorized access to the database, potentially compromising sensitive data.