Back

CVE-2004-0707

SQL injection vulnerability in editusers.cgi in Bugzilla 2.16.x before 2.16.6, and 2.18 before 2.18rc1, allows remote attackers with privileges to grant membership to any group to execute arbitrary SQL.

Published: Jul 27, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (24)

Vendor Product Version
mozilla bugzilla 2.4
mozilla bugzilla 2.6
mozilla bugzilla 2.8
mozilla bugzilla 2.10
mozilla bugzilla 2.12
mozilla bugzilla 2.14
mozilla bugzilla 2.14.1
mozilla bugzilla 2.14.2
mozilla bugzilla 2.14.3
mozilla bugzilla 2.14.4
mozilla bugzilla 2.14.5
mozilla bugzilla 2.16
mozilla bugzilla 2.16.1
mozilla bugzilla 2.16.2
mozilla bugzilla 2.16.3
mozilla bugzilla 2.16.4
mozilla bugzilla 2.16.5
mozilla bugzilla 2.17
mozilla bugzilla 2.17.1
mozilla bugzilla 2.17.3

…and 4 more

GitHub Security Advisory GHSA-wq8h-94wp-w9mg

SQL injection vulnerability in editusers.cgi in Bugzilla 2.16.x before 2.16.6, and 2.18 before 2...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.03%

Top 39% most likely to be exploited

Threat Score 30.3 / 100

Data Sources

NVD EPSS GitHub