Multiple Bugs in the Bugzilla Bug Tracking System
Remote users could gain access to other user accounts, conduct cross-site scripting attacks, or execute arbitrary SQL commands on the underlying SQL server.
Versions 2.14 and prior, also CVS version 2.15 for Unix/Linux
Solution: The vendor has released a fix. Upgrade to 2.14.1. Users of version 2.15 checked out of cvs prior to January 3, 2002 should use 'cvs update' to obtain the current cvs code.
http://www.bugzilla.org/