Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2003-1046
Description:describecomponents.cgi in Bugzilla 2.17.3 and 2.17.4 does not properly verify group membership when bug entry groups are used, which allows remote attackers to list component descriptions for otherwise restricted products.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2003-1046
BugTraq ID: 8953
http://www.securityfocus.com/bid/8953
Bugtraq: 20031103 [BUGZILLA] Security Advisory - SQL injection, information leak (Google Search)
http://www.securityfocus.com/archive/1/343185
XForce ISS Database: bugzilla-describecomponents-obtain-info(13602)
https://exchange.xforce.ibmcloud.com/vulnerabilities/13602




© 1998-2025 E-Soft Inc. All rights reserved.