CVE-2003-0013
Estado: ModificadaAlta (7.5)—
The default .htaccess scripts for Bugzilla 2.14.x before 2.14.5, 2.16.x before 2.16.2, and 2.17.x before 2.17.3 do not include filenames for backup copies of the localconfig file that are made from editors such as vi and Emacs, which could allow remote attackers to obtain a database password by directly accessing the backup file.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.08%
- Percentil entre todas las CVEs puntuadas: 81
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://marc.info/?l=bugtraq&m=104154319200399&w=2
- http://www.debian.org/security/2003/dsa-230
- http://www.iss.net/security_center/static/10970.php
- http://www.osvdb.org/6351
- http://www.securityfocus.com/bid/6501
- http://marc.info/?l=bugtraq&m=104154319200399&w=2
- http://www.debian.org/security/2003/dsa-230
- http://www.iss.net/security_center/static/10970.php
- http://www.osvdb.org/6351
- http://www.securityfocus.com/bid/6501
JSON original (NVD)
Mostrar
{
"id": "CVE-2003-0013",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2003-01-17T05:00:00.000",
"references": [
{
"url": "http://marc.info/?l=bugtraq&m=104154319200399&w=2",
"source": "cve@mitre.org"
},
{
"url": "http://www.debian.org/security/2003/dsa-230",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.iss.net/security_center/static/10970.php",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/6351",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/6501",
"source": "cve@mitre.org"
},
{
"url": "http://marc.info/?l=bugtraq&m=104154319200399&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.debian.org/security/2003/dsa-230",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.iss.net/security_center/static/10970.php",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/6351",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/6501",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The default .htaccess scripts for Bugzilla 2.14.x before 2.14.5, 2.16.x before 2.16.2, and 2.17.x before 2.17.3 do not include filenames for backup copies of the localconfig file that are made from editors such as vi and Emacs, which could allow remote attackers to obtain a database password by directly accessing the backup file."
},
{
"lang": "es",
"value": "Los scripts .htaccess por defecto en Bugzilla 2.14.x anteriores a 2.14.5, 2.16.x anteriores a 2.16.2, y 2.17.x anteriores a 2.17.3 no bloquean el acceso a copias de seguridad del fichero localconfig que son hechas por editores como vi y Emacs, lo que podría permitir a atacantes remotos obtener una contraseña de la base de datos accediendo directamente al fichero copia de seguridad."
}
],
"lastModified": "2026-06-16T22:01:20.200",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mozilla:bugzilla:2.14:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1883A98C-E595-4F3C-87BF-A63393F9F561"
},
{
"criteria": "cpe:2.3:a:mozilla:bugzilla:2.14.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DD49E53A-5676-4FAC-A8A2-30FAC04C33D7"
},
{
"criteria": "cpe:2.3:a:mozilla:bugzilla:2.14.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1084AF8E-5269-4EFF-BBD2-C5A77945FCF2"
},
{
"criteria": "cpe:2.3:a:mozilla:bugzilla:2.14.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D9A4B035-B73E-48E9-BBB9-83219F5D2A95"
},
{
"criteria": "cpe:2.3:a:mozilla:bugzilla:2.14.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9452C271-2812-4775-8396-394C642EACFD"
},
{
"criteria": "cpe:2.3:a:mozilla:bugzilla:2.16:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F16D338E-C5BC-46E1-95DD-D9B0E25EE56E"
},
{
"criteria": "cpe:2.3:a:mozilla:bugzilla:2.16.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "19F19219-3AFD-4D8E-B02B-BFCBD1BC7C36"
},
{
"criteria": "cpe:2.3:a:mozilla:bugzilla:2.17:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9B2FC5C7-B218-4B87-9805-F90AC0E7A281"
},
{
"criteria": "cpe:2.3:a:mozilla:bugzilla:2.17.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BBCDA64F-C49A-4F5B-B285-4079D8E3A499"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}