Security Advisory
CVE-2004-0707
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
SQL injection vulnerability in editusers.cgi in Bugzilla 2.16.x before 2.16.6, and 2.18 before 2.18rc1, allows remote attackers with privileges to grant membership to any group to execute arbitrary SQL.