
CVE-2002-0803
https://notcve.org/view.php?id=CVE-2002-0803
31 Jul 2002 — Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, allows remote attackers to display restricted products and components via a direct HTTP request to queryhelp.cgi. • ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SN-02%3A05.asc •

CVE-2002-0807
https://notcve.org/view.php?id=CVE-2002-0807
31 Jul 2002 — Cross-site scripting vulnerabilities in Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, could allow remote attackers to execute script as other Bugzilla users via the full name (real name) field, which is not properly quoted by editusers.cgi. • http://archives.neohapsis.com/archives/bugtraq/2002-06/0054.html •

CVE-2002-0811
https://notcve.org/view.php?id=CVE-2002-0811
31 Jul 2002 — Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, may allow remote attackers to cause a denial of service or execute certain queries via a SQL injection attack on the sort order parameter to buglist.cgi. • http://archives.neohapsis.com/archives/bugtraq/2002-06/0054.html •