Bugzilla showvotes.cgi Cross-Site Scripting Vulnerability
BID:3264
Info
Bugzilla showvotes.cgi Cross-Site Scripting Vulnerability
| Bugtraq ID: | 3264 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 29 2001 12:00AM |
| Updated: | Aug 29 2001 12:00AM |
| Credit: | This vulnerability was submitted to BugTraq on August 29th, 2001 by David Miller <[email protected]>. |
| Vulnerable: |
Mozilla Bugzilla 2.12 Mozilla Bugzilla 2.10 Mozilla Bugzilla 2.8 Mozilla Bugzilla 2.6 Mozilla Bugzilla 2.4 |
| Not Vulnerable: |
Mozilla Bugzilla 2.14 |
Discussion
Bugzilla showvotes.cgi Cross-Site Scripting Vulnerability
Bugzilla is a free, open source bug tracking and reporting appplication. It allows users to submit bugs, offers a forum for discussing bugs, keeps track of the status of bugs, and can restrict who has access to bug information.
An input validation problem exists in a Bugzilla(v2.12 and earlier) script. 'showvotes.cgi' does not strip HTML tags from requests. As a result, it is possible to submit a malicious link to a website which contains arbitrary script code. The script code will be executed in the browser of the user clicking the link, appearing to originate from the site that the malicious link was submitted to.
Variations of cross-site scripting attacks may occur as a result of this issue. Cookie-based authentication credentials may be affected, Bugzilla data may be modified remotely, etc.
Bugzilla is a free, open source bug tracking and reporting appplication. It allows users to submit bugs, offers a forum for discussing bugs, keeps track of the status of bugs, and can restrict who has access to bug information.
An input validation problem exists in a Bugzilla(v2.12 and earlier) script. 'showvotes.cgi' does not strip HTML tags from requests. As a result, it is possible to submit a malicious link to a website which contains arbitrary script code. The script code will be executed in the browser of the user clicking the link, appearing to originate from the site that the malicious link was submitted to.
Variations of cross-site scripting attacks may occur as a result of this issue. Cookie-based authentication credentials may be affected, Bugzilla data may be modified remotely, etc.
Exploit / POC
Bugzilla showvotes.cgi Cross-Site Scripting Vulnerability
This issue can be exploited with a web browser.
This issue can be exploited with a web browser.
Solution / Fix
Bugzilla showvotes.cgi Cross-Site Scripting Vulnerability
Solution:
Upgrades available:
Mozilla Bugzilla 2.10
Mozilla Bugzilla 2.12
Mozilla Bugzilla 2.8
Solution:
Upgrades available:
Mozilla Bugzilla 2.10
-
Mozilla Bugzilla 2.14
http://ftp.mozilla.org/pub/webtools/bugzilla-2.14.tar.gz -
RedHat 7.0 alpha perl-Chart-0.99c.pre3-1.alpha.rpm
ftp://updates.redhat.com/7.0/en/powertools/alpha/perl-Chart-0.99c.pre3 -1.alpha.rpm -
RedHat 7.0 alpha perl-DBD-MySQL-1.2215-1.alpha.rpm
ftp://updates.redhat.com/7.0/en/powertools/alpha/ -
RedHat 7.0 alpha perl-GD-1.33-1.alpha.rpm
ftp://updates.redhat.com/7.0/en/powertools/alpha/perl-GD-1.33-1.alpha. rpm -
RedHat 7.0 i386 perl-Chart-0.99c.pre3-1.i386.rpm
ftp://updates.redhat.com/7.0/en/powertools/i386/perl-Chart-0.99c.pre3- 1.i386.rpm -
RedHat 7.0 i386 perl-DBD-MySQL-1.2215-1.i386.rpm
ftp://updates.redhat.com/7.0/en/powertools/i386/perl-DBD-MySQL-1.2215- 1.i386.rpm -
RedHat 7.0 i386 perl-GD-1.33-1.i386.rpm
ftp://updates.redhat.com/7.0/en/powertools/i386/perl-GD-1.33-1.i386.rp m -
RedHat 7.0 noarch bugzilla-2.14-1.noarch.rpm
ftp://updates.redhat.com/7.0/en/powertools/noarch/bugzilla-2.14-1.noar ch.rpm -
RedHat 7.1 alpha perl-DBD-MySQL-1.2215-1.alpha.rpm
ftp://updates.redhat.com/7.1/en/powertools/alpha/ -
RedHat 7.1 alpha perl-GD-1.33-1.alpha.rpm
ftp://updates.redhat.com/7.1/en/powertools/alpha/perl-GD-1.33-1.alpha. rpm -
RedHat 7.1 i386 perl-Chart-0.99c.pre3-1.i386.rpm
ftp://updates.redhat.com/7.1/en/powertools/i386/ -
RedHat 7.1 i386 perl-DBD-MySQL-1.2215-1.i386.rpm
ftp://updates.redhat.com/7.1/en/powertools/i386/perl-DBD-MySQL-1.2215- 1.i386.rpm -
RedHat 7.1 i386 perl-GD-1.33-1.i386.rpm
ftp://updates.redhat.com/7.1/en/powertools/i386/perl-GD-1.33-1.i386.rp m -
RedHat 7.1 noarch bugzilla-2.14-1.noarch.rpm
ftp://updates.redhat.com/7.1/en/powertools/noarch/bugzilla-2.14-1.noar ch.rpm
Mozilla Bugzilla 2.12
-
Mozilla Bugzilla 2.14
http://ftp.mozilla.org/pub/webtools/bugzilla-2.14.tar.gz -
RedHat 7.0 alpha perl-Chart-0.99c.pre3-1.alpha.rpm
ftp://updates.redhat.com/7.0/en/powertools/alpha/perl-Chart-0.99c.pre3 -1.alpha.rpm -
RedHat 7.0 alpha perl-DBD-MySQL-1.2215-1.alpha.rpm
ftp://updates.redhat.com/7.0/en/powertools/alpha/ -
RedHat 7.0 alpha perl-GD-1.33-1.alpha.rpm
ftp://updates.redhat.com/7.0/en/powertools/alpha/perl-GD-1.33-1.alpha. rpm -
RedHat 7.0 i386 perl-Chart-0.99c.pre3-1.i386.rpm
ftp://updates.redhat.com/7.0/en/powertools/i386/perl-Chart-0.99c.pre3- 1.i386.rpm -
RedHat 7.0 i386 perl-DBD-MySQL-1.2215-1.i386.rpm
ftp://updates.redhat.com/7.0/en/powertools/i386/perl-DBD-MySQL-1.2215- 1.i386.rpm -
RedHat 7.0 i386 perl-GD-1.33-1.i386.rpm
ftp://updates.redhat.com/7.0/en/powertools/i386/perl-GD-1.33-1.i386.rp m -
RedHat 7.0 noarch bugzilla-2.14-1.noarch.rpm
ftp://updates.redhat.com/7.0/en/powertools/noarch/bugzilla-2.14-1.noar ch.rpm -
RedHat 7.1 alpha perl-DBD-MySQL-1.2215-1.alpha.rpm
ftp://updates.redhat.com/7.1/en/powertools/alpha/ -
RedHat 7.1 alpha perl-GD-1.33-1.alpha.rpm
ftp://updates.redhat.com/7.1/en/powertools/alpha/perl-GD-1.33-1.alpha. rpm -
RedHat 7.1 i386 perl-Chart-0.99c.pre3-1.i386.rpm
ftp://updates.redhat.com/7.1/en/powertools/i386/ -
RedHat 7.1 i386 perl-DBD-MySQL-1.2215-1.i386.rpm
ftp://updates.redhat.com/7.1/en/powertools/i386/perl-DBD-MySQL-1.2215- 1.i386.rpm -
RedHat 7.1 i386 perl-GD-1.33-1.i386.rpm
ftp://updates.redhat.com/7.1/en/powertools/i386/perl-GD-1.33-1.i386.rp m -
RedHat 7.1 noarch bugzilla-2.14-1.noarch.rpm
ftp://updates.redhat.com/7.1/en/powertools/noarch/bugzilla-2.14-1.noar ch.rpm
Mozilla Bugzilla 2.8
-
Mozilla Bugzilla 2.14
http://ftp.mozilla.org/pub/webtools/bugzilla-2.14.tar.gz
References
Bugzilla showvotes.cgi Cross-Site Scripting Vulnerability
References:
References: