VYPR

Bugzilla

by Python Bugzilla Project

CVEs (82)

  • CVE-2003-0013Jan 17, 2003
    risk 0.00cvss epss 0.02

    The default .htaccess scripts for Bugzilla 2.14.x before 2.14.5, 2.16.x before 2.16.2, and 2.17.x before 2.17.3 do not include filenames for backup copies of the localconfig file that are made from editors such as vi and Emacs, which could allow remote attackers to obtain a…

  • CVE-2001-0330Jun 27, 2001
    risk 0.00cvss epss 0.02

    Bugzilla 2.10 allows remote attackers to access sensitive information, including the database username and password, via an HTTP request for the globals.pl file, which is normally returned by the web server without being executed.

Page 5 of 5