Bugzilla Security Bypass and Cross Site Scripting Vulnerabilities
BID:29038
Info
Bugzilla Security Bypass and Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 29038 |
| Class: | Unknown |
| CVE: |
CVE-2008-2104 CVE-2008-2105 CVE-2008-2103 |
| Remote: | Yes |
| Local: | No |
| Published: | May 04 2008 12:00AM |
| Updated: | Jul 06 2016 02:17PM |
| Credit: | Frédéric Buclin, Max Kanat-Alexander, Bradley Baetz, Loren Butler, Marc Schumann |
| Vulnerable: |
Red Hat Fedora 7 Mozilla Bugzilla 3.1.3 Mozilla Bugzilla 2.17.7 Mozilla Bugzilla 2.17.6 Mozilla Bugzilla 2.17.5 Mozilla Bugzilla 2.17.4 Mozilla Bugzilla 2.17.3 Mozilla Bugzilla 2.17.2 |
| Not Vulnerable: |
Mozilla Bugzilla 3.1.4 Mozilla Bugzilla 3.0.4 Mozilla Bugzilla 2.22.4 Mozilla Bugzilla 2.20.6 |
Discussion
Bugzilla Security Bypass and Cross Site Scripting Vulnerabilities
Bugzilla is prone to a security-bypass and a cross-site scripting vulnerability because it fails to properly validate user credentials and sanitize user-supplied input.
An attacker may leverage the cross-site scripting issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
The attacker may leverage the security-bypass issue to modify the status of bugs, despite the attacker's insufficient privileges.
Bugzilla 2.17.2 and 3.1.3 are vulnerable; other versions may also be affected.
Bugzilla is prone to a security-bypass and a cross-site scripting vulnerability because it fails to properly validate user credentials and sanitize user-supplied input.
An attacker may leverage the cross-site scripting issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
The attacker may leverage the security-bypass issue to modify the status of bugs, despite the attacker's insufficient privileges.
Bugzilla 2.17.2 and 3.1.3 are vulnerable; other versions may also be affected.
Exploit / POC
Bugzilla Security Bypass and Cross Site Scripting Vulnerabilities
Attackers can use a browser to exploit the issues.
Attackers can use a browser to exploit the issues.
Solution / Fix
Bugzilla Security Bypass and Cross Site Scripting Vulnerabilities
Solution:
The vendor has released updates. Please see the references for more information.
Solution:
The vendor has released updates. Please see the references for more information.
References
Bugzilla Security Bypass and Cross Site Scripting Vulnerabilities
References:
References: