CVE-2002-0809

Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, does not properly handle URL-encoded field names that are generated by some browsers, which could cause certain fields to appear to be unset, which has the effect of removing group permissions on bugs when buglist.cgi is provided with the encoded field names.

Scoring

CVSS base score
0.02
EPSS probability
0.41%
Published
2003-04-02
Last modified
2026-03-16

Affected products

Markdown version · Browse all CVEs