CVE-2002-0804 affects Bugzilla versions 2.14 before 2.14.2 and 2.16 before 2.16rc2, allowing remote attackers to bypass IP restrictions. This vulnerability occurs when Bugzilla is configured for reverse DNS lookups, enabling attackers to spoof a hostname and gain unauthorized access. With a CVSS score of 7.5, it presents a high severity risk due to its network-based attack vector, low complexity, and potential for partial compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation, public exploit code, or Metasploit/Nuclei modules, the vulnerability has garnered significant community discussion with 10 mentions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.14CPE matchmatch criteria | cpe:2.3:a:mozilla:bugzilla:2.14:*:*:*:*:*:*:* | ||
2.14.1CPE matchmatch criteria | cpe:2.3:a:mozilla:bugzilla:2.14.1:*:*:*:*:*:*:* | ||
2.16CPE matchmatch criteria | cpe:2.3:a:mozilla:bugzilla:2.16:*:*:*:*:*:*:* | ||
2.16CPE matchmatch criteria | cpe:2.3:a:mozilla:bugzilla:2.16:rc1:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.