Vulnerability Details CVE-2002-1197
bugzilla_email_append.pl in Bugzilla 2.14.x before 2.14.4, and 2.16.x before 2.16.1, allows remote attackers to execute arbitrary code via shell metacharacters in a system call to processmail.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.021
EPSS Ranking 83.4%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2002-1197
-
cpe:2.3:a:mozilla:bugzilla:2.14
-
cpe:2.3:a:mozilla:bugzilla:2.14.1
-
cpe:2.3:a:mozilla:bugzilla:2.14.2
-
cpe:2.3:a:mozilla:bugzilla:2.14.3
-
cpe:2.3:a:mozilla:bugzilla:2.16