Back
CVE-2004-0707
SQL injection vulnerability in editusers.cgi in Bugzilla 2.16.x before 2.16.6, and 2.18 before 2.18rc1, allows remote attackers with privileges to grant membership to any group to execute arbitrary SQL.
Published: Jul 27, 2004
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (24)
| Vendor | Product | Version |
|---|---|---|
| mozilla | bugzilla | 2.4 |
| mozilla | bugzilla | 2.6 |
| mozilla | bugzilla | 2.8 |
| mozilla | bugzilla | 2.10 |
| mozilla | bugzilla | 2.12 |
| mozilla | bugzilla | 2.14 |
| mozilla | bugzilla | 2.14.1 |
| mozilla | bugzilla | 2.14.2 |
| mozilla | bugzilla | 2.14.3 |
| mozilla | bugzilla | 2.14.4 |
| mozilla | bugzilla | 2.14.5 |
| mozilla | bugzilla | 2.16 |
| mozilla | bugzilla | 2.16.1 |
| mozilla | bugzilla | 2.16.2 |
| mozilla | bugzilla | 2.16.3 |
| mozilla | bugzilla | 2.16.4 |
| mozilla | bugzilla | 2.16.5 |
| mozilla | bugzilla | 2.17 |
| mozilla | bugzilla | 2.17.1 |
| mozilla | bugzilla | 2.17.3 |
…and 4 more
GitHub Security Advisory GHSA-wq8h-94wp-w9mg
SQL injection vulnerability in editusers.cgi in Bugzilla 2.16.x before 2.16.6, and 2.18 before 2...
References (8)
- http://bugzilla.mozilla.org/show_bug.cgi?id=244272
- http://marc.info/?l=bugtraq&m=108965446813639&w=2
- http://www.securityfocus.com/bid/10698 Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16668
- http://bugzilla.mozilla.org/show_bug.cgi?id=244272
- http://marc.info/?l=bugtraq&m=108965446813639&w=2
- http://www.securityfocus.com/bid/10698 Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16668
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
1.03%
Top 39% most likely to be exploited
Threat Score
30.3 / 100
Data Sources
NVD
EPSS
GitHub