CVE-2004-0706: Low severity Bugzilla vulnerability
Published Jul 21, 2004
·Updated
Bugzilla 2.17.5 through 2.17.7 embeds the password in an image URL, which could allow local users to view the password in the web server log files.
Affected Software
24 affected components
Bugzilla=2.4
Bugzilla=2.6
Bugzilla=2.8
Bugzilla=2.10
Bugzilla=2.12
Bugzilla=2.14
Bugzilla=2.14.1
Bugzilla=2.14.2
Bugzilla=2.14.3
Bugzilla=2.14.4
Bugzilla=2.14.5
Bugzilla=2.16
Bugzilla=2.16.1
Bugzilla=2.16.2
Bugzilla=2.16.3
Bugzilla=2.16.4
Bugzilla=2.16.5
Bugzilla=2.17
Bugzilla=2.17.1
Bugzilla=2.17.3
Bugzilla=2.17.4
Bugzilla=2.17.5
Bugzilla=2.17.6
Bugzilla=2.17.7
Remediation
Patch Available
Event History
Jul 21, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0706?
CVE-2004-0706 is classified as a moderate severity vulnerability due to the exposure of passwords in web server logs.
2
How do I fix CVE-2004-0706?
To fix CVE-2004-0706, upgrade Bugzilla to version 2.17.8 or later, or apply patches provided by the maintainers.
3
Who is affected by CVE-2004-0706?
CVE-2004-0706 affects local users of Bugzilla versions 2.10 through 2.17.7.
4
What type of vulnerability is CVE-2004-0706?
CVE-2004-0706 is an information disclosure vulnerability associated with improper password handling.
5
How does CVE-2004-0706 exploit the system?
CVE-2004-0706 exploits the system by embedding passwords in image URLs, leading to their disclosure in server logs.