HTTP: Bugzilla Account Privilege Escalation

This signature detects attempts to exploit a known vulnerability in Bugzilla. Versions 2.14 and earlier are vulnerable. Attackers can send a maliciously crafted URL to elevate their Bugzilla account privileges; attackers can use their new status to perform more severe attacks.

Extended Description

Bugzilla is the bug tracking software package by the Mozilla project. It can be configured to run on Microsoft Windows and various Unix/Linux platforms. A vulnerability exists in the buglist.cgi script which may allow a remote attacker to modify the logic of an SQL query. Due to lack of input validation, it is possible to append arbitrary SQL to the WHERE part of a query. This may permit to the attacker to execute commands on the database.

Affected Products

Mozilla bugzilla

Short Name
HTTP:CGI:BUGZILLA:PRIV-UP
Severity
Warning
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
Account Bugzilla CVE-2002-0010 Escalation Privilege bid:3801
Release Date
04/22/2003
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Mozilla

CVSS Score

7.5

Found a potential security threat?