{"api_version":"1","generated_at":"2026-07-23T04:55:55+00:00","cve":"CVE-2001-0330","urls":{"html":"https://cve.report/CVE-2001-0330","api":"https://cve.report/api/cve/CVE-2001-0330.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2001-0330","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2001-0330"},"summary":{"title":"CVE-2001-0330","description":"Bugzilla 2.10 allows remote attackers to access sensitive information, including the database username and password, via an HTTP request for the globals.pl file, which is normally returned by the web server without being executed.","state":"PUBLISHED","assigner":"mitre","published_at":"2001-06-27 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securityfocus.com/bid/2671","name":"http://www.securityfocus.com/bid/2671","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Bugzilla Sensitive Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/6489","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/6489","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.atstake.com/research/advisories/2001/a043001-1.txt","name":"http://www.atstake.com/research/advisories/2001/a043001-1.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"","mime":"text/plain","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2001-0330","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2001-0330","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2001","cve_id":"330","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"bugzilla","cpe6":"2.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2001","cve_id":"330","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"bugzilla","cpe6":"2.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2001","cve_id":"330","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"bugzilla","cpe6":"2.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2001","cve_id":"330","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"bugzilla","cpe6":"2.8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T04:14:07.400Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"A043001-1","tags":["vendor-advisory","x_refsource_ATSTAKE","x_transferred"],"url":"http://www.atstake.com/research/advisories/2001/a043001-1.txt"},{"name":"2671","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/2671"},{"name":"bugzilla-gobalpl-gain-information(6489)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/6489"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2001-04-30T00:00:00.000Z","descriptions":[{"lang":"en","value":"Bugzilla 2.10 allows remote attackers to access sensitive information, including the database username and password, via an HTTP request for the globals.pl file, which is normally returned by the web server without being executed."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2005-11-02T10:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"A043001-1","tags":["vendor-advisory","x_refsource_ATSTAKE"],"url":"http://www.atstake.com/research/advisories/2001/a043001-1.txt"},{"name":"2671","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/2671"},{"name":"bugzilla-gobalpl-gain-information(6489)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/6489"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2001-0330","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Bugzilla 2.10 allows remote attackers to access sensitive information, including the database username and password, via an HTTP request for the globals.pl file, which is normally returned by the web server without being executed."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"A043001-1","refsource":"ATSTAKE","url":"http://www.atstake.com/research/advisories/2001/a043001-1.txt"},{"name":"2671","refsource":"BID","url":"http://www.securityfocus.com/bid/2671"},{"name":"bugzilla-gobalpl-gain-information(6489)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/6489"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2001-0330","datePublished":"2001-09-18T04:00:00.000Z","dateReserved":"2001-04-27T00:00:00.000Z","dateUpdated":"2024-08-08T04:14:07.400Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2001-06-27 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:bugzilla:2.4:*:*:*:*:*:*:*","matchCriteriaId":"8112FF13-B4CE-4DC7-85B1-C69D975F162B"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:bugzilla:2.6:*:*:*:*:*:*:*","matchCriteriaId":"86F5A3CA-E4A6-4E51-AC83-0C8F3E5E2C4E"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:bugzilla:2.8:*:*:*:*:*:*:*","matchCriteriaId":"F6E5E379-D475-42F3-B0DC-3D04C1D25566"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:bugzilla:2.10:*:*:*:*:*:*:*","matchCriteriaId":"893741D3-062B-45F9-B5A3-1B81058E7FD7"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2001","CveId":"330","Ordinal":"1","Title":"CVE-2001-0330","CVE":"CVE-2001-0330","Year":"2001"},"notes":[{"CveYear":"2001","CveId":"330","Ordinal":"1","NoteData":"Bugzilla 2.10 allows remote attackers to access sensitive information, including the database username and password, via an HTTP request for the globals.pl file, which is normally returned by the web server without being executed.","Type":"Description","Title":"CVE-2001-0330"},{"CveYear":"2001","CveId":"330","Ordinal":"2","NoteData":"2001-09-18","Type":"Other","Title":"Published"},{"CveYear":"2001","CveId":"330","Ordinal":"3","NoteData":"2005-11-02","Type":"Other","Title":"Modified"}]}}}