CVE-2001-0330
Published Jun 27, 2001
Last updated 7 years ago
Overview
- Description
- Bugzilla 2.10 allows remote attackers to access sensitive information, including the database username and password, via an HTTP request for the globals.pl file, which is normally returned by the web server without being executed.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:mozilla:bugzilla:2.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8112FF13-B4CE-4DC7-85B1-C69D975F162B" }, { "criteria": "cpe:2.3:a:mozilla:bugzilla:2.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "86F5A3CA-E4A6-4E51-AC83-0C8F3E5E2C4E" }, { "criteria": "cpe:2.3:a:mozilla:bugzilla:2.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F6E5E379-D475-42F3-B0DC-3D04C1D25566" }, { "criteria": "cpe:2.3:a:mozilla:bugzilla:2.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "893741D3-062B-45F9-B5A3-1B81058E7FD7" } ], "operator": "OR" } ] } ]