AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2002-0010

HIGH · CVSS 7.5 EPSS 2.28%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2002-01-31 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.5. It may be remotely exploitable.

CVE
CVE-2002-0010
Severity
HIGH
CVSS
7.5
EPSS
2.28%

Original NVD Description

Bugzilla before 2.14.1 allows remote attackers to inject arbitrary SQL code and create files or gain privileges via (1) the sql parameter in buglist.cgi, (2) invalid field names from the "boolean chart" query in buglist.cgi, (3) the mybugslink parameter in userprefs.cgi, (4) a malformed bug ID in the buglist parameter in long_list.cgi, and (5) the value parameter in editusers.cgi, which allows groupset privileges to be modified by attackers with blessgroupset privileges.