« Volver al listado

CVE-2003-1045

Estado: ModificadaMedia (5)—

votes.cgi in Bugzilla 2.16.3 and earlier, and 2.17.1 through 2.17.4, allows remote attackers to read a user's voting page when that user has voted on a restricted bug, which allows remote attackers to read potentially sensitive voting information by modifying the who parameter.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2003-1045",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2004-08-18T04:00:00.000",
  "references": [
    {
      "url": "http://bugzilla.mozilla.org/show_bug.cgi?id=209376",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000774",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/343185",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/8953",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/13600",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://bugzilla.mozilla.org/show_bug.cgi?id=209376",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000774",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/343185",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/8953",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/13600",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "votes.cgi in Bugzilla 2.16.3 and earlier, and 2.17.1 through 2.17.4, allows remote attackers to read a user's voting page when that user has voted on a restricted bug, which allows remote attackers to read potentially sensitive voting information by modifying the who parameter."
    },
    {
      "lang": "es",
      "value": "votes.cgi en Bugzilla 2.16.3 y anteriores, y 2.17.1 a 2.17.4 permite a atacantes remotos leer la página de votos de un usuario cuando el usuario ha votado sobre un bug restringido, lo que permite a atacantes remotos leer información sensible de votación modificando el parámetro who."
    }
  ],
  "lastModified": "2026-06-16T22:03:25.367",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8112FF13-B4CE-4DC7-85B1-C69D975F162B"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "86F5A3CA-E4A6-4E51-AC83-0C8F3E5E2C4E"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F6E5E379-D475-42F3-B0DC-3D04C1D25566"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "893741D3-062B-45F9-B5A3-1B81058E7FD7"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.12:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E8D53B5F-6AEE-4192-B838-E1DA92C59285"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.14:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1883A98C-E595-4F3C-87BF-A63393F9F561"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.14.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DD49E53A-5676-4FAC-A8A2-30FAC04C33D7"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.14.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1084AF8E-5269-4EFF-BBD2-C5A77945FCF2"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.14.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D9A4B035-B73E-48E9-BBB9-83219F5D2A95"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.14.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9452C271-2812-4775-8396-394C642EACFD"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.14.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2D351AF2-C0AB-4BB3-8692-677A3025A615"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.16:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F16D338E-C5BC-46E1-95DD-D9B0E25EE56E"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.16.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "19F19219-3AFD-4D8E-B02B-BFCBD1BC7C36"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.16.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B900D9A7-913A-4176-90CF-C7C3B09A4261"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.16.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B692910E-633D-4A88-B245-56A2B58DD4CB"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.17.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BBCDA64F-C49A-4F5B-B285-4079D8E3A499"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.17.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "85ED3457-CC21-4DB3-931F-677F723E1B2A"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.17.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6C8711D3-55CF-4131-BBAC-6BE07068219F"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}