Back

CVE-2003-1042

SQL injection vulnerability in collectstats.pl for Bugzilla 2.16.3 and earlier allows remote authenticated users with editproducts privileges to execute arbitrary SQL via the product name.

Published: Aug 18, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (18)

Vendor Product Version
mozilla bugzilla 2.4
mozilla bugzilla 2.6
mozilla bugzilla 2.8
mozilla bugzilla 2.10
mozilla bugzilla 2.12
mozilla bugzilla 2.14
mozilla bugzilla 2.14.1
mozilla bugzilla 2.14.2
mozilla bugzilla 2.14.3
mozilla bugzilla 2.14.4
mozilla bugzilla 2.14.5
mozilla bugzilla 2.16
mozilla bugzilla 2.16.1
mozilla bugzilla 2.16.2
mozilla bugzilla 2.16.3
mozilla bugzilla 2.17.1
mozilla bugzilla 2.17.3
mozilla bugzilla 2.17.4

GitHub Security Advisory GHSA-phj7-qm5x-fx2h

SQL injection vulnerability in collectstats.pl for Bugzilla 2.16.3 and earlier allows remote...

Risk Scores

CVSS Score 10.0 / 10
EPSS Score 2.57%

Top 16% most likely to be exploited

Threat Score 40.8 / 100

Data Sources

NVD EPSS GitHub