Back

CVE-2006-0913

SQL injection vulnerability in whineatnews.pl in Bugzilla 2.17 through 2.18.4 and 2.20 allows remote authenticated users with administrative privileges to execute arbitrary SQL commands via the whinedays parameter, as accessible from editparams.cgi.

Published: Feb 28, 2006 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (22)

Vendor Product Version
mozilla bugzilla 2.17.1
mozilla bugzilla 2.17.3
mozilla bugzilla 2.17.4
mozilla bugzilla 2.17.5
mozilla bugzilla 2.17.6
mozilla bugzilla 2.17.7
mozilla bugzilla 2.18
mozilla bugzilla 2.18
mozilla bugzilla 2.18
mozilla bugzilla 2.18.1
mozilla bugzilla 2.18.2
mozilla bugzilla 2.18.3
mozilla bugzilla 2.18.4
mozilla bugzilla 2.19
mozilla bugzilla 2.19.1
mozilla bugzilla 2.19.2
mozilla bugzilla 2.19.3
mozilla bugzilla 2.20
mozilla bugzilla 2.20
mozilla bugzilla 2.20

…and 2 more

GitHub Security Advisory GHSA-46fm-qcpg-4p27

SQL injection vulnerability in whineatnews.pl in Bugzilla 2.17 through 2.18.4 and 2.20 allows...

Risk Scores

CVSS Score 5.5 / 10
EPSS Score 1.04%

Top 39% most likely to be exploited

Threat Score 22.3 / 100

Data Sources

NVD EPSS GitHub