LiveActive security incident?Get immediate response
CVE archive

2001 CVE Archive

Browse CVE records published in 2001 CVE Archive, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1537 matching CVEs · Page 5 of 31.

Unknown · CVSS Not scored

CVE-2001-1401: Bugzilla before 2.14 does not properly restrict access to confidential bugs, which could allow Bugzilla use...

Bugzilla before 2.14 does not properly restrict access to confidential bugs, which could allow Bugzilla users to bypass viewing permissions via modified bug id parameters in (1) process_bug.cgi, (2) show_activity.cgi, (3) showvotes.cgi, (4) showdependencytree.cgi, (5) showdependencygraph.cgi, (6) showattachment.cgi, or (7) describecomponents.cgi.

Published Aug 31, 2002 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2001-1402: Bugzilla before 2.14 does not properly escape untrusted parameters, which could allow remote attackers to c...

Bugzilla before 2.14 does not properly escape untrusted parameters, which could allow remote attackers to conduct unauthorized activities via cross-site scripting (CSS) and possibly SQL injection attacks on (1) the product or output form variables for reports.cgi, (2) the voteon, bug_id, and user variables for showvotes.cgi, (3) an invalid email address in createaccount.cgi, (4) an invalid ID in showdependencytree.cgi, (5) invalid usernames and other fields in process_bug.cgi, and (6) error messages in buglist.cgi.

Published Aug 31, 2002 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2001-1370: prepend.php3 in PHPLib before 7.2d, when register_globals is enabled for PHP, allows remote attackers to ex...

prepend.php3 in PHPLib before 7.2d, when register_globals is enabled for PHP, allows remote attackers to execute arbitrary scripts via an HTTP request that modifies $_PHPLIB[libdir] to point to malicious code on another server, as seen in Horde 1.2.5 and earlier, IMP before 2.2.6, and other packages that use PHPLib.

Published Apr 2, 2003 · Updated Aug 8, 2024