security flaw
Published Jan 10, 2002
7.5
HIGHCVSS 2.0
EPSS 2.28%
Description
Bugzilla before 2.14.1 allows remote attackers to inject arbitrary SQL code and create files or gain privileges via (1) the sql parameter in buglist.cgi, (2) invalid field names from the "boolean chart" query in buglist.cgi, (3) the mybugslink parameter in userprefs.cgi, (4) a malformed bug ID in the buglist parameter in long_list.cgi, and (5) the value parameter in editusers.cgi, which allows groupset privileges to be modified by attackers with blessgroupset privileges.
Affected products
No data.
No data.
Red Hat Powertools 7.0
n/a
Fixed · RHSA-2002:001
Red Hat Powertools 7.1
n/a
Fixed · RHSA-2002:001
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Powertools 7.0 | n/a | Fixed | RHSA-2002:001 |
| Red Hat Powertools 7.1 | n/a | Fixed | RHSA-2002:001 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (9 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 2.28% (0.02281) | 82.52th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.28% (0.02281) | 80.81th | v5 (v2026.06.15) |
| Mar 17, 2025 | 3.71% (0.03710) | 87.17th | v4 (v2025.03.14) |
| Dec 12, 2024 | 1.06% (0.01063) | 84.81th | v3 (v2023.03.01) |
| Apr 10, 2024 | 1.06% (0.01063) | 83.91th | v3 (v2023.03.01) |
| Mar 7, 2023 | 1.06% (0.01063) | 81.90th | v3 (v2023.03.01) |
| Mar 6, 2023 | 4.36% (0.04358) | 88.02th | v2 (v2022.01.01) |
| Apr 1, 2022 | 4.36% (0.04358) | 86.83th | v2 (v2022.01.01) |
| Feb 4, 2022 | 4.36% (0.04358) | 70.59th | v2 (v2022.01.01) |
No CWE recorded.
References (23)
- http://archives.neohapsis.com/archives/bugtraq/2002-01/0034.html mailing-listx_refsource_BUGTRAQPatchVendor Advisory
- http://archives.neohapsis.com/archives/bugtraq/2002-01/0052.html mailing-listx_refsource_BUGTRAQ
- http://bugzilla.mozilla.org/show_bug.cgi?id=108812 x_refsource_MISC
- http://bugzilla.mozilla.org/show_bug.cgi?id=108821 x_refsource_MISC
- http://bugzilla.mozilla.org/show_bug.cgi?id=108822 x_refsource_MISC
- http://bugzilla.mozilla.org/show_bug.cgi?id=109679 x_refsource_MISC
- http://bugzilla.mozilla.org/show_bug.cgi?id=109690 x_refsource_MISC
- http://rhn.redhat.com/errata/RHSA-2002-001.html vendor-advisoryx_refsource_REDHAT
- http://www.bugzilla.org/bugzilla2.14to2.14.1.patch x_refsource_MISC
- http://www.bugzilla.org/security2_14_1.html x_refsource_CONFIRM
- http://www.iss.net/security_center/static/7807.php vdb-entryx_refsource_XF
- http://www.iss.net/security_center/static/7809.php vdb-entryx_refsource_XF
- http://www.iss.net/security_center/static/7811.php vdb-entryx_refsource_XF
- http://www.iss.net/security_center/static/7813.php vdb-entryx_refsource_XF
- http://www.iss.net/security_center/static/7814.php vdb-entryx_refsource_XF
- http://www.securityfocus.com/bid/3801 vdb-entryx_refsource_BID
- http://www.securityfocus.com/bid/3802 vdb-entryx_refsource_BID
- http://www.securityfocus.com/bid/3804 vdb-entryx_refsource_BID
- http://www.securityfocus.com/bid/3805 vdb-entryx_refsource_BID
- https://access.redhat.com/security/cve/CVE-2002-0010 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1616718 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2002-0010
- https://www.cve.org/CVERecord?id=CVE-2002-0010
Change history (0)
No recorded changes yet.