Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, directs error messages from the syncshadowdb command to the HTML output, which could leak sensitive information, including plaintext passwords, if syncshadowdb fails.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-08T03:03:49.280Z
Reserved: 2002-07-29T00:00:00
Link: CVE-2002-0810

No data.

Status : Modified
Published: 2002-08-12T04:00:00.000
Modified: 2024-11-20T23:39:55.423
Link: CVE-2002-0810
