CVE-2001-1403

critical

Description

Bugzilla before 2.14 includes the username and password in URLs, which could allow attackers to gain privileges by reading the information from the web server logs, or by "shoulder-surfing" and observing the web browser's location bar.

References

http://www.redhat.com/support/errata/RHSA-2001-107.html

http://marc.info/?l=bugtraq&m=99912899900567

http://bugzilla.mozilla.org/show_bug.cgi?id=15980

Details

Source: Mitre, NVD

Published: 2001-09-10

Updated: 2026-06-16

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 9.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Severity: Critical

EPSS

EPSS: 0.00527