Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2002-0007

Overview

Vulnerability Score 10.0 10.0
CVE Id CVE-2002-0007
Last Modified 10 Sep 2008 03:11:02
Published 31 Jan 2002 12:00:00
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2002-0007

Summary

CGI.pl in Bugzilla before 2.14.1, when using LDAP, allows remote attackers to obtain an anonymous bind to the LDAP server via a request that does not include a password, which causes a null password to be sent to the LDAP server.

Vulnerable Systems

Application

  • Mozilla Bugzilla 2.14.1


References

BUGTRAQ - 20020105 Security Advisory for Bugzilla v2.15 (cvs20020103) and older

CONFIRM - http://www.bugzilla.org/security2_14_1.html

MISC - http://bugzilla.mozilla.org/show_bug.cgi?id=54901

XF - bugzilla-ldap-auth-bypass(7812)

BID - 3792

REDHAT - RHSA-2002:001


Last Updated: 27 May 2016 10:36:44