CVE-2001-1403

Bugzilla before 2.14 includes the username and password in URLs, which could allow attackers to gain privileges by reading the information from the web server logs, or by "shoulder-surfing" and observing the web browser's location bar.

Scoring

CVSS base score
0.03
EPSS probability
0.53%
Published
2002-08-31
Last modified
2026-03-16

Affected products

Markdown version · Browse all CVEs