{"api_version":"1","generated_at":"2026-07-22T23:41:27+00:00","cve":"CVE-2002-0807","urls":{"html":"https://cve.report/CVE-2002-0807","api":"https://cve.report/api/cve/CVE-2002-0807.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2002-0807","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2002-0807"},"summary":{"title":"CVE-2002-0807","description":"Cross-site scripting vulnerabilities in Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, could allow remote attackers to execute script as other Bugzilla users via the full name (real name) field, which is not properly quoted by editusers.cgi.","state":"PUBLISHED","assigner":"mitre","published_at":"2002-08-12 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.iss.net/security_center/static/9304.php","name":"http://www.iss.net/security_center/static/9304.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ISS X-Force Database: bugzilla-real-name-xss (9304): Bugzilla `Real Name` field cross-site scripting","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://archives.neohapsis.com/archives/bugtraq/2002-06/0054.html","name":"http://archives.neohapsis.com/archives/bugtraq/2002-06/0054.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Neohapsis Archives - Bugtraq - [BUGZILLA] Security Advisory For Versions of Bugzilla 2.14 Prior To   2.14.2, 2.16 Prior To 2.16rc2 - From justdavesyndicomm.com","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://bugzilla.mozilla.org/show_bug.cgi?id=146447","name":"http://bugzilla.mozilla.org/show_bug.cgi?id=146447","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"146447 – cross-site scripting bug with bugzilla user's name","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/4964","name":"http://www.securityfocus.com/bid/4964","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Multiple Bugzilla Security Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2002-0807","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2002-0807","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2002","cve_id":"807","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"bugzilla","cpe6":"2.14","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"807","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"bugzilla","cpe6":"2.14.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"807","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"bugzilla","cpe6":"2.16","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"807","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"bugzilla","cpe6":"2.16","cpe7":"rc1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T03:03:48.554Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"bugzilla-real-name-xss(9304)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"http://www.iss.net/security_center/static/9304.php"},{"name":"4964","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/4964"},{"name":"20020608 [BUGZILLA] Security Advisory For Versions of Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://archives.neohapsis.com/archives/bugtraq/2002-06/0054.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://bugzilla.mozilla.org/show_bug.cgi?id=146447"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2002-06-08T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting vulnerabilities in Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, could allow remote attackers to execute script as other Bugzilla users via the full name (real name) field, which is not properly quoted by editusers.cgi."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2007-11-01T00:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"bugzilla-real-name-xss(9304)","tags":["vdb-entry","x_refsource_XF"],"url":"http://www.iss.net/security_center/static/9304.php"},{"name":"4964","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/4964"},{"name":"20020608 [BUGZILLA] Security Advisory For Versions of Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://archives.neohapsis.com/archives/bugtraq/2002-06/0054.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://bugzilla.mozilla.org/show_bug.cgi?id=146447"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2002-0807","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting vulnerabilities in Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, could allow remote attackers to execute script as other Bugzilla users via the full name (real name) field, which is not properly quoted by editusers.cgi."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"bugzilla-real-name-xss(9304)","refsource":"XF","url":"http://www.iss.net/security_center/static/9304.php"},{"name":"4964","refsource":"BID","url":"http://www.securityfocus.com/bid/4964"},{"name":"20020608 [BUGZILLA] Security Advisory For Versions of Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2","refsource":"BUGTRAQ","url":"http://archives.neohapsis.com/archives/bugtraq/2002-06/0054.html"},{"name":"http://bugzilla.mozilla.org/show_bug.cgi?id=146447","refsource":"CONFIRM","url":"http://bugzilla.mozilla.org/show_bug.cgi?id=146447"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2002-0807","datePublished":"2002-07-31T04:00:00.000Z","dateReserved":"2002-07-29T00:00:00.000Z","dateUpdated":"2024-08-08T03:03:48.554Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2002-08-12 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":true,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:bugzilla:2.14:*:*:*:*:*:*:*","matchCriteriaId":"1883A98C-E595-4F3C-87BF-A63393F9F561"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:bugzilla:2.14.1:*:*:*:*:*:*:*","matchCriteriaId":"DD49E53A-5676-4FAC-A8A2-30FAC04C33D7"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:bugzilla:2.16:*:*:*:*:*:*:*","matchCriteriaId":"F16D338E-C5BC-46E1-95DD-D9B0E25EE56E"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:bugzilla:2.16:rc1:*:*:*:*:*:*","matchCriteriaId":"5877CECA-F758-4F48-B4F4-2C4C1DF01FA0"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2002","CveId":"807","Ordinal":"1","Title":"CVE-2002-0807","CVE":"CVE-2002-0807","Year":"2002"},"notes":[{"CveYear":"2002","CveId":"807","Ordinal":"1","NoteData":"Cross-site scripting vulnerabilities in Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, could allow remote attackers to execute script as other Bugzilla users via the full name (real name) field, which is not properly quoted by editusers.cgi.","Type":"Description","Title":"CVE-2002-0807"},{"CveYear":"2002","CveId":"807","Ordinal":"2","NoteData":"2002-07-31","Type":"Other","Title":"Published"},{"CveYear":"2002","CveId":"807","Ordinal":"3","NoteData":"2007-10-31","Type":"Other","Title":"Modified"}]}}}