Bugzilla HTML Injection and Cross Site Request Forgery Vulnerabilities
BID:33580
Info
Bugzilla HTML Injection and Cross Site Request Forgery Vulnerabilities
| Bugtraq ID: | 33580 |
| Class: | Design Error |
| CVE: |
CVE-2009-0481 CVE-2009-0482 CVE-2009-0483 CVE-2009-0484 CVE-2009-0485 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 02 2009 12:00AM |
| Updated: | Apr 13 2015 09:21PM |
| Credit: | Fr&eacute;d&eacute;ric Buclin, Stephen Lee, Jesse Ruderman, Terry Weissman, Max Kanat-Alexander, Teemu Mannermaa, Mozilla Corporation <br> |
| Vulnerable: |
Mozilla Bugzilla 3.3.1 Mozilla Bugzilla 3.0.6 Mozilla Bugzilla 3.0.5 Mozilla Bugzilla 3.0.4 Mozilla Bugzilla 3.0.2 Mozilla Bugzilla 3.0.1 Mozilla Bugzilla 3.0 Mozilla Bugzilla 2.22.6 Mozilla Bugzilla 2.22.5 Mozilla Bugzilla 2.22.4 Mozilla Bugzilla 2.22.3 Mozilla Bugzilla 2.22.2 Mozilla Bugzilla 2.22.1 Mozilla Bugzilla 3.2 Mozilla Bugzilla 2.22 RC1 Mozilla Bugzilla 2.22 Gentoo Linux |
| Not Vulnerable: |
Mozilla Bugzilla 3.3.2 Mozilla Bugzilla 3.2.1 Mozilla Bugzilla 3.0.7 Mozilla Bugzilla 2.22.7 |
Discussion
Bugzilla HTML Injection and Cross Site Request Forgery Vulnerabilities
Bugzilla is prone to multiple remote vulnerabilities, including an HTML-injection issue and cross-site request-forgery issues.
An attacker can exploit these issues to execute arbitrary script code in a user's browser in the context of the application, steal cookie-based authentication credentials, obtain sensitive information, and perform arbitrary actions in the context of the logged-in user.
These issues affect versions prior to Bugzilla 2.22.7, 3.0.7, 3.2.1, and 3.3.2.
Bugzilla is prone to multiple remote vulnerabilities, including an HTML-injection issue and cross-site request-forgery issues.
An attacker can exploit these issues to execute arbitrary script code in a user's browser in the context of the application, steal cookie-based authentication credentials, obtain sensitive information, and perform arbitrary actions in the context of the logged-in user.
These issues affect versions prior to Bugzilla 2.22.7, 3.0.7, 3.2.1, and 3.3.2.
Exploit / POC
Bugzilla HTML Injection and Cross Site Request Forgery Vulnerabilities
An attacker can exploit these issues through a browser. To exploit some of these issues, the attacker must entice a user into visiting a malicious site.
An attacker can exploit these issues through a browser. To exploit some of these issues, the attacker must entice a user into visiting a malicious site.
Solution / Fix
Bugzilla HTML Injection and Cross Site Request Forgery Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Bugzilla HTML Injection and Cross Site Request Forgery Vulnerabilities
References:
References:
- Bugzilla Homepage (Mozilla)
- 3.2, 3.0.6, 2.22.6, and 3.3.1 Security Advisory (Mozilla)