{"api_version":"1","generated_at":"2026-07-22T23:41:12+00:00","cve":"CVE-2002-0809","urls":{"html":"https://cve.report/CVE-2002-0809","api":"https://cve.report/api/cve/CVE-2002-0809.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2002-0809","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2002-0809"},"summary":{"title":"CVE-2002-0809","description":"Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, does not properly handle URL-encoded field names that are generated by some browsers, which could cause certain fields to appear to be unset, which has the effect of removing group permissions on bugs when buglist.cgi is provided with the encoded field names.","state":"PUBLISHED","assigner":"mitre","published_at":"2002-08-12 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.iss.net/security_center/static/10141.php","name":"http://www.iss.net/security_center/static/10141.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ISS X-Force Database: bugzilla-group-permissions-removal (10141): Bugzilla URL encoded field names could remove group permissions on bugs","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://archives.neohapsis.com/archives/bugtraq/2002-06/0054.html","name":"http://archives.neohapsis.com/archives/bugtraq/2002-06/0054.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Neohapsis Archives - Bugtraq - [BUGZILLA] Security Advisory For Versions of Bugzilla 2.14 Prior To   2.14.2, 2.16 Prior To 2.16rc2 - From justdavesyndicomm.com","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/4964","name":"http://www.securityfocus.com/bid/4964","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Multiple Bugzilla Security Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.redhat.com/support/errata/RHSA-2002-109.html","name":"http://www.redhat.com/support/errata/RHSA-2002-109.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://bugzilla.mozilla.org/show_bug.cgi?id=148674","name":"http://bugzilla.mozilla.org/show_bug.cgi?id=148674","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"148674 – Boolean Charts don't work in Netpositive because '-' is sent as '%2D'","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2002-0809","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2002-0809","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2002","cve_id":"809","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"bugzilla","cpe6":"2.14","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"809","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"bugzilla","cpe6":"2.14.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"809","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"bugzilla","cpe6":"2.16","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"809","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"bugzilla","cpe6":"2.16","cpe7":"rc1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T03:03:49.340Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"4964","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/4964"},{"name":"20020608 [BUGZILLA] Security Advisory For Versions of Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://archives.neohapsis.com/archives/bugtraq/2002-06/0054.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://bugzilla.mozilla.org/show_bug.cgi?id=148674"},{"name":"bugzilla-group-permissions-removal(10141)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"http://www.iss.net/security_center/static/10141.php"},{"name":"RHSA-2002:109","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2002-109.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2002-06-08T00:00:00.000Z","descriptions":[{"lang":"en","value":"Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, does not properly handle URL-encoded field names that are generated by some browsers, which could cause certain fields to appear to be unset, which has the effect of removing group permissions on bugs when buglist.cgi is provided with the encoded field names."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2003-03-24T00:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"4964","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/4964"},{"name":"20020608 [BUGZILLA] Security Advisory For Versions of Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://archives.neohapsis.com/archives/bugtraq/2002-06/0054.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://bugzilla.mozilla.org/show_bug.cgi?id=148674"},{"name":"bugzilla-group-permissions-removal(10141)","tags":["vdb-entry","x_refsource_XF"],"url":"http://www.iss.net/security_center/static/10141.php"},{"name":"RHSA-2002:109","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2002-109.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2002-0809","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, does not properly handle URL-encoded field names that are generated by some browsers, which could cause certain fields to appear to be unset, which has the effect of removing group permissions on bugs when buglist.cgi is provided with the encoded field names."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"4964","refsource":"BID","url":"http://www.securityfocus.com/bid/4964"},{"name":"20020608 [BUGZILLA] Security Advisory For Versions of Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2","refsource":"BUGTRAQ","url":"http://archives.neohapsis.com/archives/bugtraq/2002-06/0054.html"},{"name":"http://bugzilla.mozilla.org/show_bug.cgi?id=148674","refsource":"CONFIRM","url":"http://bugzilla.mozilla.org/show_bug.cgi?id=148674"},{"name":"bugzilla-group-permissions-removal(10141)","refsource":"XF","url":"http://www.iss.net/security_center/static/10141.php"},{"name":"RHSA-2002:109","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2002-109.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2002-0809","datePublished":"2003-04-02T05:00:00.000Z","dateReserved":"2002-07-29T00:00:00.000Z","dateUpdated":"2024-08-08T03:03:49.340Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2002-08-12 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:bugzilla:2.14:*:*:*:*:*:*:*","matchCriteriaId":"1883A98C-E595-4F3C-87BF-A63393F9F561"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:bugzilla:2.14.1:*:*:*:*:*:*:*","matchCriteriaId":"DD49E53A-5676-4FAC-A8A2-30FAC04C33D7"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:bugzilla:2.16:*:*:*:*:*:*:*","matchCriteriaId":"F16D338E-C5BC-46E1-95DD-D9B0E25EE56E"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:bugzilla:2.16:rc1:*:*:*:*:*:*","matchCriteriaId":"5877CECA-F758-4F48-B4F4-2C4C1DF01FA0"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2002","CveId":"809","Ordinal":"1","Title":"CVE-2002-0809","CVE":"CVE-2002-0809","Year":"2002"},"notes":[{"CveYear":"2002","CveId":"809","Ordinal":"1","NoteData":"Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, does not properly handle URL-encoded field names that are generated by some browsers, which could cause certain fields to appear to be unset, which has the effect of removing group permissions on bugs when buglist.cgi is provided with the encoded field names.","Type":"Description","Title":"CVE-2002-0809"},{"CveYear":"2002","CveId":"809","Ordinal":"2","NoteData":"2003-04-02","Type":"Other","Title":"Published"},{"CveYear":"2002","CveId":"809","Ordinal":"3","NoteData":"2003-03-23","Type":"Other","Title":"Modified"}]}}}