PT-2004-1786 · Mozilla · Bugzilla
Published
2004-07-21
·
Updated
2017-07-11
·
CVE-2004-0706
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Bugzilla versions 2.17.5 through 2.17.7
Description
The issue allows local users to view passwords in web server log files because the password is embedded in an image URL.
Recommendations
For versions 2.17.5 through 2.17.7, consider restricting access to the web server log files to minimize the risk of password exposure until a fix is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bugzilla