CVE-2001-1403
Bugzilla before 2.14 includes the username and password in URLs, which could allow attackers to gain privileges by reading the information from the web server logs, or by "shoulder-surfing" and observing the web browser's location bar.
Scoring
- CVSS base score
- 0.03
- EPSS probability
- 0.53%
- Published
- 2002-08-31
- Last modified
- 2026-03-16
Affected products
- n/a n/a