CVE-2002-0810

Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, directs error messages from the syncshadowdb command to the HTML output, which could leak sensitive information, including plaintext passwords, if syncshadowdb fails.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:bugzilla:2.14:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.14.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.16:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.16:rc1:*:*:*:*:*:*

History

No history.

Information

Published : 2002-08-12 04:00

Updated : 2023-12-10 10:17


NVD link : CVE-2002-0810

Mitre link : CVE-2002-0810

CVE.ORG link : CVE-2002-0810


JSON object : View

Products Affected

mozilla

  • bugzilla